Merge pull request #111011 from waldheinz/nginx-mem-write-exec

nixos/nginx: fix MemoryDenyWriteExecute not being disabled when needed

Changed files
+1 -1
nixos
modules
services
web-servers
nginx
+1 -1
nixos/modules/services/web-servers/nginx/default.nix
···
ProtectControlGroups = true;
RestrictAddressFamilies = [ "AF_UNIX" "AF_INET" "AF_INET6" ];
LockPersonality = true;
-
MemoryDenyWriteExecute = !(builtins.any (mod: (mod.allowMemoryWriteExecute or false)) pkgs.nginx.modules);
+
MemoryDenyWriteExecute = !(builtins.any (mod: (mod.allowMemoryWriteExecute or false)) cfg.package.modules);
RestrictRealtime = true;
RestrictSUIDSGID = true;
PrivateMounts = true;