lol

nixos/galene: set proper SystemCallFilter

+1 -1
+1 -1
nixos/modules/services/web-apps/galene.nix
··· 191 191 RestrictRealtime = true; 192 192 RestrictSUIDSGID = true; 193 193 SystemCallArchitectures = "native"; 194 - SystemCallFilter = [ "@system-service" "~@privileged" "~@resources" ]; 194 + SystemCallFilter = [ "@system-service" "~@privileged" ]; 195 195 UMask = "0077"; 196 196 } 197 197 ];