mirror of
https://github.com/NixOS/nixpkgs.git
synced 2026-10-03 13:30:36 +00:00
nixos/release-notes: mention monero hardening
Co-authored-by: rnhmjoj <rnhmjoj@inventati.org>
This commit is contained in:
@@ -164,6 +164,8 @@
|
||||
and the default changed to a UNIX domain socket.
|
||||
- A cookie-cutter nginx vhost can be enabled at [](#opt-services.netbox.nginx.enable).
|
||||
|
||||
- The [monero](#opt-services.monero.enable) systemd service has been security hardened.
|
||||
|
||||
- `security.run0.enableSudoAlias` now uses the `run0-sudo-shim` instead of a shell-script to improve compatibility.
|
||||
|
||||
- With `system.etc.overlay.mutable = false`, NixOS now ships an empty `/etc/machine-id` in the image. Previously the file was absent and systemd logged `System cannot boot: Missing /etc/machine-id and /etc/ is read-only` while `ConditionFirstBoot` fired on every boot. With this change, systemd now overlays a transient ID from `/run/machine-id` for the session, and `systemd-machine-id-commit.service` has `ConditionFirstBoot` so it writes the machine-id through to a persistent backing file when one is bind-mounted over `/etc/machine-id`. To persist the machine-id across reboots, bind-mount a writable file containing `uninitialized` over `/etc/machine-id` from the initrd, or set `systemd.machine_id=` on the kernel command line (use `systemd.machine_id=firmware` to derive a stable ID on hardware that supports it).
|
||||
|
||||
Reference in New Issue
Block a user