nixos: make setgid wrappers root-owned

rnhmjoj 31790c81 378d2c5d

Changed files
+8 -8
nixos
modules
programs
services
mail
x11
desktop-managers
+1 -1
nixos/modules/programs/ccache.nix
···
# "nix-ccache --show-stats" and "nix-ccache --clear"
security.wrappers.nix-ccache = {
-
owner = "nobody";
+
owner = "root";
group = "nixbld";
setuid = false;
setgid = true;
+1 -1
nixos/modules/programs/mosh.nix
···
security.wrappers = mkIf cfg.withUtempter {
utempter = {
source = "${pkgs.libutempter}/lib/utempter/utempter";
-
owner = "nobody";
+
owner = "root";
group = "utmp";
setuid = false;
setgid = true;
+1 -1
nixos/modules/services/mail/opensmtpd.nix
···
};
security.wrappers.smtpctl = {
-
owner = "nobody";
+
owner = "root";
group = "smtpq";
setuid = false;
setgid = true;
+4 -4
nixos/modules/services/mail/postfix.nix
···
services.mail.sendmailSetuidWrapper = mkIf config.services.postfix.setSendmail {
program = "sendmail";
source = "${pkgs.postfix}/bin/sendmail";
-
owner = "nobody";
+
owner = "root";
group = setgidGroup;
setuid = false;
setgid = true;
···
security.wrappers.mailq = {
program = "mailq";
source = "${pkgs.postfix}/bin/mailq";
-
owner = "nobody";
+
owner = "root";
group = setgidGroup;
setuid = false;
setgid = true;
···
security.wrappers.postqueue = {
program = "postqueue";
source = "${pkgs.postfix}/bin/postqueue";
-
owner = "nobody";
+
owner = "root";
group = setgidGroup;
setuid = false;
setgid = true;
···
security.wrappers.postdrop = {
program = "postdrop";
source = "${pkgs.postfix}/bin/postdrop";
-
owner = "nobody";
+
owner = "root";
group = setgidGroup;
setuid = false;
setgid = true;
+1 -1
nixos/modules/services/x11/desktop-managers/cde.nix
···
security.wrappers = {
dtmail = {
setgid = true;
-
owner = "nobody";
+
owner = "root";
group = "mail";
source = "${pkgs.cdesktopenv}/bin/dtmail";
};