privoxy service: additional isolation

Changed files
+5
nixos
modules
services
networking
+5
nixos/modules/services/networking/privoxy.nix
···
after = [ "network.target" "nss-lookup.target" ];
wantedBy = [ "multi-user.target" ];
serviceConfig.ExecStart = "${privoxy}/sbin/privoxy --no-daemon --user ${privoxyUser} ${confFile}";
+
+
serviceConfig.PrivateDevices = true;
+
serviceConfig.PrivateTmp = true;
+
serviceConfig.ProtectHome = true;
+
serviceConfig.ProtectSystem = "full";
};
};