[Backport release-24.11] nixos/zigbee2mqtt: only add port to DeviceAllow if it is a device (#356582)

This commit is contained in:
Nick Cao 2024-11-17 09:19:11 -05:00 committed by GitHub
commit 9156f19e52
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194

View File

@ -76,9 +76,7 @@ in
# Hardening
CapabilityBoundingSet = "";
DeviceAllow = [
config.services.zigbee2mqtt.settings.serial.port
];
DeviceAllow = lib.optionals (lib.hasPrefix "/" cfg.settings.serial.port) [ cfg.settings.serial.port ];
DevicePolicy = "closed";
LockPersonality = true;
MemoryDenyWriteExecute = false;