nixos-module: fix LimitNOFILE case
This commit is contained in:
parent
c3c67a54e4
commit
35782d3617
|
@ -250,7 +250,7 @@ in
|
||||||
RestrictRealtime = true;
|
RestrictRealtime = true;
|
||||||
LockPersonality = true;
|
LockPersonality = true;
|
||||||
MemoryDenyWriteExecute = true;
|
MemoryDenyWriteExecute = true;
|
||||||
LimitNOFile = limitNOFILE;
|
LimitNOFILE = limitNOFILE;
|
||||||
LimitRSS = "4G";
|
LimitRSS = "4G";
|
||||||
MemoryMax = "16G";
|
MemoryMax = "16G";
|
||||||
};
|
};
|
||||||
|
@ -279,7 +279,7 @@ in
|
||||||
RestrictRealtime = true;
|
RestrictRealtime = true;
|
||||||
LockPersonality = true;
|
LockPersonality = true;
|
||||||
MemoryDenyWriteExecute = true;
|
MemoryDenyWriteExecute = true;
|
||||||
LimitNOFile = limitNOFILE;
|
LimitNOFILE = limitNOFILE;
|
||||||
MemoryMax = "2G";
|
MemoryMax = "2G";
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
@ -307,7 +307,7 @@ in
|
||||||
RestrictRealtime = true;
|
RestrictRealtime = true;
|
||||||
LockPersonality = true;
|
LockPersonality = true;
|
||||||
MemoryDenyWriteExecute = true;
|
MemoryDenyWriteExecute = true;
|
||||||
LimitNOFile = limitNOFILE;
|
LimitNOFILE = limitNOFILE;
|
||||||
WorkingDirectory = "${pkgs.caveman-gatherer}/share/caveman/gatherer";
|
WorkingDirectory = "${pkgs.caveman-gatherer}/share/caveman/gatherer";
|
||||||
MemoryMax = "1G";
|
MemoryMax = "1G";
|
||||||
};
|
};
|
||||||
|
@ -354,7 +354,7 @@ in
|
||||||
RestrictRealtime = true;
|
RestrictRealtime = true;
|
||||||
LockPersonality = true;
|
LockPersonality = true;
|
||||||
MemoryDenyWriteExecute = true;
|
MemoryDenyWriteExecute = true;
|
||||||
LimitNOFile = limitNOFILE;
|
LimitNOFILE = limitNOFILE;
|
||||||
LimitRSS = "128M:256M";
|
LimitRSS = "128M:256M";
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
@ -382,7 +382,7 @@ in
|
||||||
RestrictRealtime = true;
|
RestrictRealtime = true;
|
||||||
LockPersonality = true;
|
LockPersonality = true;
|
||||||
MemoryDenyWriteExecute = true;
|
MemoryDenyWriteExecute = true;
|
||||||
LimitNOFile = limitNOFILE;
|
LimitNOFILE = limitNOFILE;
|
||||||
LimitRSS = "64M:256M";
|
LimitRSS = "64M:256M";
|
||||||
# Allow listening on ports <1024
|
# Allow listening on ports <1024
|
||||||
AmbientCapabilities = "CAP_NET_BIND_SERVICE";
|
AmbientCapabilities = "CAP_NET_BIND_SERVICE";
|
||||||
|
|
Loading…
Reference in New Issue