From cd7129a037465ea36d95848561d7a00c72db3062 Mon Sep 17 00:00:00 2001 From: Eelco Dolstra Date: Fri, 5 Sep 2014 14:43:11 +0200 Subject: [PATCH] Revert "nixos: add setuid wrappers for some networked filesystems' helpers" This reverts commit 26a4001a98322ab903b8186b97f33c5b282828a5. It breaks the NFS test: http://hydra.nixos.org/build/13943148 Also, having more setuid programs is a bad thing security-wise. --- nixos/modules/security/setuid-wrappers.nix | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/nixos/modules/security/setuid-wrappers.nix b/nixos/modules/security/setuid-wrappers.nix index 22dbdf6a6bf4..373afffd3fb5 100644 --- a/nixos/modules/security/setuid-wrappers.nix +++ b/nixos/modules/security/setuid-wrappers.nix @@ -77,9 +77,7 @@ in config = { security.setuidPrograms = - [ "mount.nfs" "mount.nfs4" "mount.cifs" - "fusermount" "umount" - "wodim" "cdrdao" "growisofs" ]; + [ "fusermount" "wodim" "cdrdao" "growisofs" ]; system.activationScripts.setuid = let