!DBFhtjpqmJNENpLDOv:nixos.org

NixOS systemd

599 Members
NixOS ❤️ systemd167 Servers

Load older messages


SenderMessageTime
28 May 2021
@jkarlson:kapsi.fiEmil Karlson set a profile picture.10:04:01
@okpedersen:matrix.orgokpedersen joined the room.13:07:57
29 May 2021
@ochoa:matrix.orgOchoa joined the room.02:31:20
@justinrestivo:matrix.orgjustinrestivo changed their display name from justinrestivo to oh caml >>=.12:20:55
@justinrestivo:matrix.orgjustinrestivo changed their profile picture.12:21:58
@justinrestivo:matrix.orgjustinrestivo changed their display name from oh caml >>= to justinrestivo.12:22:25
@justinrestivo:matrix.orgjustinrestivo changed their profile picture.12:23:57
@mkos:matrix.orgMark left the room.19:13:37
@cyplo:cyplo.devcyplo joined the room.19:58:51
@antifuchs:asf.computerantifuchs joined the room.22:37:13
@antifuchs:asf.computerantifuchs set a profile picture.22:49:09
31 May 2021
@morrpl:matrix.orgmorrpl joined the room.00:09:42
@0x4a6f:matrix.org[0x4A6F] changed their display name from [0x4A6F] to 0x4A6F.08:24:28
@isti115:matrix.orgisti115 joined the room.09:22:01
@jfroche:matrix.orgjfroche joined the room.18:35:26
1 Jun 2021
@0x4a6f:matrix.org[0x4A6F] changed their display name from 0x4A6F to [0x4A6F].06:36:29
@sgo:matrix.orgstigo left the room.13:14:47
3 Jun 2021
@andi:kack.itandi-I know I talked about it a few times on IRC but I finally sat down and implemented an experiment to provide opt-in hardening for services: https://github.com/andir/nixpkgs/commit/4d9c0cfdab5d681ff0372bf8b5a2ac6e650c9b8c17:22:39
@andi:kack.itandi-Merging of lists with default values is really bad.. If you want to opt-in to one feature but don't want to repeat the entire exclude list (which is the default value) it becomes repetitive again.18:12:12
@aaron:fosslib.netaaron andi-: in my opinion this is significantly better than what has been proposed in the past 19:43:54
@aaron:fosslib.netaaron ❤️ andi- 19:44:03
@aaron:fosslib.netaaroni just quickly looked at it... i'll read it when i have more time, but i like this approach more19:44:55
@andi:kack.itandi-We still have a problem of exlcluding a single mitigation in one of the larger lists but I'll keep iterating20:06:20
@Las:matrix.orgLas

andi-:

This commit introduces a new
systemd.services.<service-name>.defaultHarddefaultHardening option
that allows specifiying a profile level that should be applied.

20:39:28
@Las:matrix.orgLasI assume this is a typo?20:39:35
@andi:kack.itandi-the long option name? If so, yes.21:25:30
4 Jun 2021
@antifuchs:asf.computerantifuchsoh, this is pretty neat!00:29:37
@roosemberth:orbstheorem.chRoos andi-: That looks awesome. 00:32:46
@roosemberth:orbstheorem.chRoosWhat's the policy on changing those hardening options?00:33:01
@roosemberth:orbstheorem.chRoosAlso, is there a eta-reduction I don't understand or is the unitConfig argument unused? :/00:35:41

Show newer messages


Back to Room ListRoom Version: 6