forked from mirrors/nixpkgs
nixos/endlessh-go: set proper SystemCallFilter
This commit is contained in:
parent
db029623b7
commit
7415970a3e
|
@ -126,7 +126,7 @@ in
|
|||
RestrictRealtime = true;
|
||||
RestrictSUIDSGID = true;
|
||||
SystemCallArchitectures = "native";
|
||||
SystemCallFilter = [ "@system-service" "~@resources" "~@privileged" ];
|
||||
SystemCallFilter = [ "@system-service" "~@privileged" ];
|
||||
};
|
||||
};
|
||||
|
||||
|
|
Loading…
Reference in a new issue