From 54610aaddcc01e335c34087bc0c3bc1de6d23cf8 Mon Sep 17 00:00:00 2001 From: Ophestra Date: Mon, 15 Dec 2025 12:43:58 +0900 Subject: internal/outcome: expose pipewire via pipewire-pulse This no longer exposes the pipewire socket to the container, and instead mediates access via pipewire-pulse. This makes insecure parts of the protocol inaccessible as explained in the doc comment in hst. Closes #29. Signed-off-by: Ophestra --- options.nix | 10 +--------- 1 file changed, 1 insertion(+), 9 deletions(-) (limited to 'options.nix') diff --git a/options.nix b/options.nix index 1d3d6a16..db3f2c21 100644 --- a/options.nix +++ b/options.nix @@ -242,19 +242,11 @@ in type = nullOr bool; default = true; description = '' - Whether to share the PipeWire server via SecurityContext. + Whether to share the PipeWire server via pipewire-pulse on a SecurityContext socket. ''; }; }; - pulse = mkOption { - type = nullOr bool; - default = true; - description = '' - Whether to run the PulseAudio compatibility daemon. - ''; - }; - share = mkOption { type = nullOr package; default = null; -- cgit v1.3.1