lol

nixos/geoipupdate: set proper SystemCallFilter

+1 -1
+1 -1
nixos/modules/services/misc/geoipupdate.nix
··· 197 197 ProtectKernelTunables = true; 198 198 ProtectProc = "invisible"; 199 199 ProcSubset = "pid"; 200 - SystemCallFilter = [ "@system-service" "~@privileged" "~@resources" ]; 200 + SystemCallFilter = [ "@system-service" "~@privileged" ]; 201 201 RestrictAddressFamilies = [ "AF_INET" "AF_INET6" ]; 202 202 RestrictRealtime = true; 203 203 RestrictNamespaces = true;