-
-
Notifications
You must be signed in to change notification settings - Fork 12.7k
Commit
- Loading branch information
There are no files selected for viewing
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -21,15 +21,15 @@ with lib; | |
description = "Disable kernel module loading"; | ||
|
||
wantedBy = [ config.systemd.defaultUnit ]; | ||
after = [ "systemd-udev-settle.service" "firewall.service" "systemd-modules-load.service" ] ++ wantedBy; | ||
|
||
script = "echo -n 1 > /proc/sys/kernel/modules_disabled"; | ||
after = [ "systemd-udev-settle.service" "firewall.service" "systemd-modules-load.service" ] ++ wantedBy; | ||
|
||
unitConfig.ConditionPathIsReadWrite = "/proc/sys/kernel"; | ||
|
||
serviceConfig = { | ||
Type = "oneshot"; | ||
RemainAfterExit = true; | ||
ExecStart = "/bin/sh -c 'echo -n 1 >/proc/sys/kernel/modules_disabled'"; | ||
This comment has been minimized.
Sorry, something went wrong.
This comment has been minimized.
Sorry, something went wrong.
joachifm
Author
Contributor
|
||
}; | ||
}; | ||
}; | ||
|
2 comments
on commit 15a4f9d
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
What is the simplification here? Using ExecStart
instead of script
seems more verbose...
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
If you do systemctl cat disable-kernel-module-loading
, you can immediately see the effective command
without looking at the generated script. Also it saves building one derivation.
out of curiosity: Could this not be replaced by
sysctl -w
?