nixos/clash-verge: move IPC path to /run/clash-verge-rev/service.sock for better security

wxt 4b5d9e4a b222541e

Changed files
+3 -2
nixos
modules
programs
+3 -2
nixos/modules/programs/clash-verge.nix
···
ProtectControlGroups = true;
LockPersonality = true;
RestrictRealtime = true;
+
RuntimeDirectory = "clash-verge-rev";
ProtectClock = true;
MemoryDenyWriteExecute = true;
RestrictSUIDSGID = true;
-
RestrictNamespaces = [ "~user cgroup ipc mnt uts" ];
+
RestrictNamespaces = [ "~user cgroup mnt uts" ];
RestrictAddressFamilies = [
-
"AF_INET AF_INET6 AF_NETLINK AF_PACKET AF_RAW"
+
"AF_INET AF_INET6 AF_NETLINK AF_PACKET AF_UNIX"
];
CapabilityBoundingSet = [
"CAP_NET_ADMIN CAP_NET_RAW CAP_SYS_ADMIN CAP_DAC_OVERRIDE CAP_SETUID CAP_SETGID CAP_CHOWN CAP_MKNOD"