lol

nixos/nats: set proper SystemCallFilter

+1 -1
+1 -1
nixos/modules/services/networking/nats.nix
··· 137 137 RestrictNamespaces = true; 138 138 RestrictRealtime = true; 139 139 RestrictSUIDSGID = true; 140 - SystemCallFilter = [ "@system-service" "~@privileged" "~@resources" ]; 140 + SystemCallFilter = [ "@system-service" "~@privileged" ]; 141 141 UMask = "0077"; 142 142 } 143 143 ];