|
|
@ -390,7 +390,7 @@ let
|
|
|
|
# USB stick, nothing is mistakenly written to persistent storage.
|
|
|
|
# USB stick, nothing is mistakenly written to persistent storage.
|
|
|
|
boot.kernelParams = [ "copytoram" ];
|
|
|
|
boot.kernelParams = [ "copytoram" ];
|
|
|
|
# Secure defaults
|
|
|
|
# Secure defaults
|
|
|
|
boot.cleanTmpDir = true;
|
|
|
|
boot.tmp.cleanOnBoot = true;
|
|
|
|
boot.kernel.sysctl = { "kernel.unprivileged_bpf_disabled" = 1; };
|
|
|
|
boot.kernel.sysctl = { "kernel.unprivileged_bpf_disabled" = 1; };
|
|
|
|
|
|
|
|
|
|
|
|
services.pcscd.enable = true;
|
|
|
|
services.pcscd.enable = true;
|
|
|
|