nixos/systemd: run0: enable setLoginUid, disable pamMount (#428459)

This commit is contained in:
Florian Klink 2025-07-26 19:51:50 +02:00 committed by GitHub
commit e9df8b4e2f
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194

View File

@ -838,7 +838,11 @@ in
# error that were trying to avoid cant possibly happen if polkit isnt enabled. When polkit isnt
# enabled, run0 will fail before it even tries to run the command.
security.pam.services = mkIf config.security.polkit.enable {
systemd-run0 = { };
systemd-run0 = {
# Upstream config: https://github.com/systemd/systemd/blob/main/src/run/systemd-run0.in
setLoginUid = true;
pamMount = false;
};
};
};