nixos/hardened: simplify script

Changed files
+2 -2
nixos
modules
+2 -2
nixos/modules/security/lock-kernel-modules.nix
···
description = "Disable kernel module loading";
wantedBy = [ config.systemd.defaultUnit ];
-
after = [ "systemd-udev-settle.service" "firewall.service" "systemd-modules-load.service" ] ++ wantedBy;
-
script = "echo -n 1 > /proc/sys/kernel/modules_disabled";
+
after = [ "systemd-udev-settle.service" "firewall.service" "systemd-modules-load.service" ] ++ wantedBy;
unitConfig.ConditionPathIsReadWrite = "/proc/sys/kernel";
serviceConfig = {
Type = "oneshot";
RemainAfterExit = true;
+
ExecStart = "/bin/sh -c 'echo -n 1 >/proc/sys/kernel/modules_disabled'";
};
};
};