about summary refs log tree commit diff
path: root/nixos/modules/security
AgeCommit message (Expand)AuthorFilesLines
2023-10-20Merge pull request #253764 from linj-fork/fix-ping-wrapperMartin Weinelt1-6/+0
2023-10-16Merge pull request #255547 from Majiir/pam-modular-rulesSilvan Mosberger1-356/+392
2023-10-11nixos/modules/security/wrappers: drop dead codeedef1-8/+0
2023-10-10nixos/pam: add maintainerMajiir Paktu1-0/+2
2023-10-10nixos/pam: generate apparmor includes from rulesMajiir Paktu1-85/+13
2023-10-10nixos/pam: add order comment to each rule lineMajiir Paktu1-0/+1
2023-10-10nixos/pam: convert rules to attrs, add order fieldMajiir Paktu1-7/+43
2023-10-10nixos/pam: remove empty text fieldsMajiir Paktu1-177/+85
2023-10-10nixos/pam: add settings option for common argument stylesMajiir Paktu1-163/+176
2023-10-10nixos/security/wrappers: don't force PIE hardening (#259509)Ben Wolsieffer1-1/+0
2023-10-09nixos/pam: extract args fieldMajiir Paktu1-97/+190
2023-10-09nixos/pam: extract modulePath fieldMajiir Paktu1-174/+144
2023-10-09nixos/pam: extract control fieldMajiir Paktu1-172/+178
2023-10-09nixos/pam: give each rule a nameMajiir Paktu1-85/+91
2023-10-09nixos/pam: define rules as submodulesMajiir Paktu1-183/+205
2023-10-09nixos/pam: automatically populate rule typeMajiir Paktu1-86/+88
2023-10-09nixos/pam: extract header commentsMajiir Paktu1-182/+227
2023-10-05nixos/security/wrappers: use musl rather than glibc and explicitly unset inse...edef3-3/+73
2023-09-24nixos/pam: split rule lists into individual rulesMajiir Paktu1-0/+10
2023-09-24nixos/pam: clean up rulesMajiir Paktu1-22/+16
2023-09-22nixos/sudo-rs: add crossCompile 'fix'Maciej Krüger1-1/+1
2023-09-22nixos/sudo-rs: initMaciej Krüger1-9/+9
2023-09-22nixos/sudo: revert sudo-rs 922926cfbc08f3e4065b51a41ebf613e59888015 (partial ...Maciej Krüger2-98/+367
2023-09-21nixos/network-interfaces: stop wrapping ping with cap_net_rawLin Jian1-6/+0
2023-09-18nixos/sudo: Add myself as maintainernicoo1-0/+2
2023-09-18nixos/sudo: Generate `sudo-i` PAM config for interactive use of `sudo-rs`nicoo1-1/+4
2023-09-18nixos/sudo: Only wrap `sudoedit` when using Miller's sudonicoo1-1/+2
2023-09-18nixos/{sudo, terminfo}: Adjust defaults for compatibility with `sudo-rs`nicoo1-6/+4
2023-09-18nixos/sudo: Check syntax using the configured packagenicoo1-3/+1
2023-09-18nixos/sudo: Drop the sudoers comment for `extraRules`nicoo1-13/+10
2023-09-18nixos/sudo: Make the default rules' options configurablenicoo1-2/+11
2023-09-18nixos/sudo: Handle `root`'s default rule through `extraRules`nicoo1-11/+21
2023-09-18nixos/sudo: Drop useless `lib.` qualifiersnicoo1-26/+23
2023-09-18nixos/sudo: Refactor checks for Todd C. Miller's implemetationnicoo1-3/+5
2023-09-18nixos/sudo: Refactor option definitionsnicoo1-8/+8
2023-09-18nixos/sudo: Only keep SSH_AUTH_SOCK if used for authenticationnicoo1-2/+6
2023-09-18nixos/sudo: Don't include empty sectionsnicoo1-6/+6
2023-09-18nixos/sudo: Split up `configFile` into individual sectionsnicoo1-6/+12
2023-09-11nixos/acme: rename option credentialsFile to environmentFiledatafoo2-6/+10
2023-09-11nixos/acme: add option to set credential filesdatafoo1-0/+31
2023-09-11nixos/pam: fix typo in fscrypt enable optionmib1-1/+1
2023-09-10Merge pull request #251770 from robryk/suidwrapapparmPierre Bourdon3-114/+19
2023-09-09security/acme: limit concurrent certificate generationsOliver Schmidt1-13/+93
2023-09-04nixos/sudo: Guard against `security.sudo.package = pkgs.sudo-rs;`nicoo1-0/+4
2023-08-27nixos/security/wrappers: remove all the assertions about readlink(/proc/self/...Robert Obryk3-84/+2
2023-08-27nixos/security/wrappers: read capabilities off /proc/self/exe directlyRobert Obryk1-1/+1
2023-08-27nixos/security/wrappers: stop using `.real` filesRobert Obryk3-32/+16
2023-08-27nixos/security/wrappers: generate a separate and more complete apparmor polic...Robert Obryk1-3/+6
2023-08-24Revert "nixos/security/wrappers: simplifications and a fix for #98863"Pierre Bourdon3-13/+110
2023-08-16nixos/security/wrappers: remove all the assertions about readlink(/proc/self/...Robert Obryk3-84/+2