nixos/meilisearch: allow access to proc for memory limit (#442565)

h7x4 30a76b36 f2e6aba3

Changed files
+3 -1
nixos
modules
services
+3 -1
nixos/modules/services/search/meilisearch.nix
···
LockPersonality = true;
MemoryDenyWriteExecute = true;
-
ProcSubset = "pid";
+
# Meilisearch needs to determine cgroup memory limits to set its own memory limits.
+
# This means this can't be set to "pid"
+
ProcSubset = "all";
ProtectProc = "invisible";
NoNewPrivileges = true;