dspam service: restrict socket access

Changed files
+1
nixos
modules
services
mail
+1
nixos/modules/services/mail/dspam.nix
···
User = cfg.user;
Group = cfg.group;
RuntimeDirectory = optional (cfg.domainSocket == defaultSock) "dspam";
+
RuntimeDirectoryMode = optional (cfg.domainSocket == defaultSock) "0750";
PermissionsStartOnly = true;
# DSPAM segfaults on just about every error
Restart = "on-failure";