nixos: services: woodpecker: exec: fix NodeJS
All checks were successful
ci/woodpecker/push/check Pipeline was successful

I need it for Tree Sitter support...
This commit is contained in:
Bruno BELANYI 2024-04-08 21:19:54 +02:00
parent 6b51b4e2ab
commit 6efe2c12ba

View file

@ -44,6 +44,8 @@ in
serviceConfig = { serviceConfig = {
# Same option as upstream, without @setuid # Same option as upstream, without @setuid
SystemCallFilter = lib.mkForce "~@clock @privileged @cpu-emulation @debug @keyring @module @mount @obsolete @raw-io @reboot @swap"; SystemCallFilter = lib.mkForce "~@clock @privileged @cpu-emulation @debug @keyring @module @mount @obsolete @raw-io @reboot @swap";
# NodeJS requires RWX memory...
MemoryDenyWriteExecute = lib.mkForce false;
BindPaths = [ BindPaths = [
"/nix/var/nix/daemon-socket/socket" "/nix/var/nix/daemon-socket/socket"