tangled
alpha
login
or
join now
pyrox.dev
/
nixpkgs
0
fork
atom
lol
0
fork
atom
overview
issues
pulls
pipelines
nixos/croc: set proper SystemCallFilter
MidAutumnMoon
3 years ago
ba8041fc
19b481fb
+1
-1
1 changed file
expand all
collapse all
unified
split
nixos
modules
services
networking
croc.nix
+1
-1
nixos/modules/services/networking/croc.nix
···
72
72
RuntimeDirectoryMode = "700";
73
73
SystemCallFilter = [
74
74
"@system-service"
75
75
-
"~@aio" "~@keyring" "~@memlock" "~@privileged" "~@resources" "~@setuid" "~@sync" "~@timer"
75
75
+
"~@aio" "~@keyring" "~@memlock" "~@privileged" "~@setuid" "~@sync" "~@timer"
76
76
];
77
77
SystemCallArchitectures = "native";
78
78
SystemCallErrorNumber = "EPERM";