Merge pull request #182342 from veehaitch/github-runner-capset

nixos/github-runner: fix capset syscall filtering

authored by winter.bsky.social and committed by GitHub 2922becf 4152f64e

+1 -1
+1 -1
nixos/modules/services/continuous-integration/github-runner.nix
··· 300 UMask = "0066"; 301 ProtectProc = "invisible"; 302 SystemCallFilter = [ 303 - "~@capset" 304 "~@clock" 305 "~@cpu-emulation" 306 "~@module" ··· 308 "~@obsolete" 309 "~@raw-io" 310 "~@reboot" 311 "~setdomainname" 312 "~sethostname" 313 ];
··· 300 UMask = "0066"; 301 ProtectProc = "invisible"; 302 SystemCallFilter = [ 303 "~@clock" 304 "~@cpu-emulation" 305 "~@module" ··· 307 "~@obsolete" 308 "~@raw-io" 309 "~@reboot" 310 + "~capset" 311 "~setdomainname" 312 "~sethostname" 313 ];