tangled
alpha
login
or
join now
pyrox.dev
/
nixpkgs
0
fork
atom
lol
0
fork
atom
overview
issues
pulls
pipelines
nixos/galene: set proper SystemCallFilter
MidAutumnMoon
3 years ago
19b481fb
29571c9c
+1
-1
1 changed file
expand all
collapse all
unified
split
nixos
modules
services
web-apps
galene.nix
+1
-1
nixos/modules/services/web-apps/galene.nix
···
191
191
RestrictRealtime = true;
192
192
RestrictSUIDSGID = true;
193
193
SystemCallArchitectures = "native";
194
194
-
SystemCallFilter = [ "@system-service" "~@privileged" "~@resources" ];
194
194
+
SystemCallFilter = [ "@system-service" "~@privileged" ];
195
195
UMask = "0077";
196
196
}
197
197
];