From 8bd2e5942e30be4746e7f88a4dd0cd0de1e8f174 Mon Sep 17 00:00:00 2001 From: Emmet Date: Sun, 23 Jun 2024 20:26:40 -0500 Subject: [PATCH] Prevent non-root from creating new profiles --- harden.sh | 1 + 1 file changed, 1 insertion(+) diff --git a/harden.sh b/harden.sh index 5e8f5e5..e1d65d5 100755 --- a/harden.sh +++ b/harden.sh @@ -25,6 +25,7 @@ chown -R 0:0 system; chown -R 0:0 patches; chown 0:0 flake.lock; chown 0:0 flake.nix +chown 0:0 profiles chown 0:0 profiles/*/configuration.nix; chown 0:0 harden.sh; chown 0:0 soften.sh;