monero: systemd service sandboxing configuration (#499861)

This commit is contained in:
Michele Guerini Rocco
2026-07-31 05:09:05 +00:00
committed by GitHub
2 changed files with 37 additions and 1 deletions

View File

@@ -164,6 +164,8 @@
and the default changed to a UNIX domain socket.
- A cookie-cutter nginx vhost can be enabled at [](#opt-services.netbox.nginx.enable).
- The [monero](#opt-services.monero.enable) systemd service has been security hardened.
- `security.run0.enableSudoAlias` now uses the `run0-sudo-shim` instead of a shell-script to improve compatibility.
- With `system.etc.overlay.mutable = false`, NixOS now ships an empty `/etc/machine-id` in the image. Previously the file was absent and systemd logged `System cannot boot: Missing /etc/machine-id and /etc/ is read-only` while `ConditionFirstBoot` fired on every boot. With this change, systemd now overlays a transient ID from `/run/machine-id` for the session, and `systemd-machine-id-commit.service` has `ConditionFirstBoot` so it writes the machine-id through to a persistent backing file when one is bind-mounted over `/etc/machine-id`. To persist the machine-id across reboots, bind-mount a writable file containing `uninitialized` over `/etc/machine-id` from the initrd, or set `systemd.machine_id=` on the kernel command line (use `systemd.machine_id=firmware` to derive a stable ID on hardware that supports it).

View File

@@ -271,7 +271,7 @@ in
group = "monero";
description = "Monero daemon user";
home = cfg.dataDir;
createHome = true;
createHome = !(lib.strings.hasPrefix "/var/lib/" cfg.dataDir);
};
users.groups.monero = { };
@@ -298,6 +298,40 @@ in
0
1
];
StateDirectory = lib.mkIf (lib.strings.hasPrefix "/var/lib/" cfg.dataDir) (
lib.strings.removePrefix "/var/lib/" cfg.dataDir
);
ReadWritePaths = lib.mkIf (!(lib.strings.hasPrefix "/var/lib/" cfg.dataDir)) [ cfg.dataDir ];
WorkingDirectory = "${cfg.dataDir}";
LockPersonality = lib.mkDefault true;
NoNewPrivileges = lib.mkDefault true;
PrivateDevices = lib.mkDefault true;
PrivateMounts = lib.mkDefault true;
PrivateNetwork = lib.mkDefault false;
PrivateTmp = lib.mkDefault true;
PrivateUsers = lib.mkDefault true;
ProcSubset = lib.mkDefault "pid";
ProtectClock = lib.mkDefault true;
ProtectHome = lib.mkDefault true;
ProtectHostname = lib.mkDefault true;
ProtectSystem = lib.mkDefault "strict";
ProtectControlGroups = lib.mkDefault true;
ProtectKernelLogs = lib.mkDefault true;
ProtectKernelModules = lib.mkDefault true;
ProtectKernelTunables = lib.mkDefault true;
ProtectProc = lib.mkDefault "invisible";
CapabilityBoundingSet = lib.mkDefault "";
RemoveIPC = lib.mkDefault true;
RestrictNamespaces = lib.mkDefault true;
RestrictRealtime = lib.mkDefault true;
RestrictSUIDSGID = lib.mkDefault true;
SystemCallFilter = "@system-service";
UMask = "0077";
RestrictAddressFamilies = [
"AF_INET"
"AF_INET6"
"AF_NETLINK"
];
};
};