From 7010563632fd7eef006c16d92c8ecc1d1bf83104 Mon Sep 17 00:00:00 2001 From: Jennings Zhang Date: Sat, 14 Mar 2026 12:00:50 -0400 Subject: [PATCH 1/2] monero: systemd service hardening configuration --- nixos/modules/services/networking/monero.nix | 36 +++++++++++++++++++- 1 file changed, 35 insertions(+), 1 deletion(-) diff --git a/nixos/modules/services/networking/monero.nix b/nixos/modules/services/networking/monero.nix index 5c0388aee32a..32821ed270c6 100644 --- a/nixos/modules/services/networking/monero.nix +++ b/nixos/modules/services/networking/monero.nix @@ -271,7 +271,7 @@ in group = "monero"; description = "Monero daemon user"; home = cfg.dataDir; - createHome = true; + createHome = !(lib.strings.hasPrefix "/var/lib/" cfg.dataDir); }; users.groups.monero = { }; @@ -298,6 +298,40 @@ in 0 1 ]; + StateDirectory = lib.mkIf (lib.strings.hasPrefix "/var/lib/" cfg.dataDir) ( + lib.strings.removePrefix "/var/lib/" cfg.dataDir + ); + ReadWritePaths = lib.mkIf (!(lib.strings.hasPrefix "/var/lib/" cfg.dataDir)) [ cfg.dataDir ]; + WorkingDirectory = "${cfg.dataDir}"; + LockPersonality = lib.mkDefault true; + NoNewPrivileges = lib.mkDefault true; + PrivateDevices = lib.mkDefault true; + PrivateMounts = lib.mkDefault true; + PrivateNetwork = lib.mkDefault false; + PrivateTmp = lib.mkDefault true; + PrivateUsers = lib.mkDefault true; + ProcSubset = lib.mkDefault "pid"; + ProtectClock = lib.mkDefault true; + ProtectHome = lib.mkDefault true; + ProtectHostname = lib.mkDefault true; + ProtectSystem = lib.mkDefault "strict"; + ProtectControlGroups = lib.mkDefault true; + ProtectKernelLogs = lib.mkDefault true; + ProtectKernelModules = lib.mkDefault true; + ProtectKernelTunables = lib.mkDefault true; + ProtectProc = lib.mkDefault "invisible"; + CapabilityBoundingSet = lib.mkDefault ""; + RemoveIPC = lib.mkDefault true; + RestrictNamespaces = lib.mkDefault true; + RestrictRealtime = lib.mkDefault true; + RestrictSUIDSGID = lib.mkDefault true; + SystemCallFilter = "@system-service"; + UMask = "0077"; + RestrictAddressFamilies = [ + "AF_INET" + "AF_INET6" + "AF_NETLINK" + ]; }; }; From 841966b41f4bfecda7c5a8475c54a3eead2ce76a Mon Sep 17 00:00:00 2001 From: Jennings Zhang Date: Thu, 30 Jul 2026 18:23:19 -0400 Subject: [PATCH 2/2] nixos/release-notes: mention monero hardening Co-authored-by: rnhmjoj --- nixos/doc/manual/release-notes/rl-2611.section.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/nixos/doc/manual/release-notes/rl-2611.section.md b/nixos/doc/manual/release-notes/rl-2611.section.md index d9d9193ac45f..5636d1553b88 100644 --- a/nixos/doc/manual/release-notes/rl-2611.section.md +++ b/nixos/doc/manual/release-notes/rl-2611.section.md @@ -164,6 +164,8 @@ and the default changed to a UNIX domain socket. - A cookie-cutter nginx vhost can be enabled at [](#opt-services.netbox.nginx.enable). +- The [monero](#opt-services.monero.enable) systemd service has been security hardened. + - `security.run0.enableSudoAlias` now uses the `run0-sudo-shim` instead of a shell-script to improve compatibility. - With `system.etc.overlay.mutable = false`, NixOS now ships an empty `/etc/machine-id` in the image. Previously the file was absent and systemd logged `System cannot boot: Missing /etc/machine-id and /etc/ is read-only` while `ConditionFirstBoot` fired on every boot. With this change, systemd now overlays a transient ID from `/run/machine-id` for the session, and `systemd-machine-id-commit.service` has `ConditionFirstBoot` so it writes the machine-id through to a persistent backing file when one is bind-mounted over `/etc/machine-id`. To persist the machine-id across reboots, bind-mount a writable file containing `uninitialized` over `/etc/machine-id` from the initrd, or set `systemd.machine_id=` on the kernel command line (use `systemd.machine_id=firmware` to derive a stable ID on hardware that supports it).