nixos/virtualbox: Revert disable hardening.

This reverts commit 5d67b17901.

The issues have been resolved by ac603e208c.

Tested this with hostonlyifs and USB support with extension pack.

Conflicts:
	nixos/modules/programs/virtualbox-host.nix

Signed-off-by: aszlig <aszlig@redmoonstudios.org>
Tested-by: Mateusz Kowalczyk <fuuzetsu@fuuzetsu.co.uk>
This commit is contained in:
aszlig 2014-12-18 18:12:25 +01:00
parent 06e6d7def2
commit f7384b8c75
No known key found for this signature in database
GPG key ID: D0EBD0EC8C2DC961

View file

@ -35,7 +35,7 @@ in
enableHardening = mkOption {
type = types.bool;
default = false;
default = true;
description = ''
Enable hardened VirtualBox, which ensures that only the binaries in the
system path get access to the devices exposed by the kernel modules
@ -54,13 +54,6 @@ in
boot.extraModulePackages = [ virtualbox ];
environment.systemPackages = [ virtualbox ];
warnings = mkIf (!cfg.enableHardening) (singleton (
"Hardening is currently disabled for VirtualBox, because of some " +
"issues in conjunction with host-only-interfaces. If you don't use " +
"hostonlyifs, it's strongly recommended to set " +
"`services.virtualboxHost.enableHardening = true'!"
));
security.setuidOwners = let
mkSuid = program: {
inherit program;