forked from mirrors/nixpkgs
nixos/nginx: fix SystemCallFilter after 1fc113f0df
This commit is contained in:
parent
1fc113f0df
commit
c408cd921f
|
@ -896,7 +896,7 @@ in
|
|||
PrivateMounts = true;
|
||||
# System Call Filtering
|
||||
SystemCallArchitectures = "native";
|
||||
SystemCallFilter = "~@cpu-emulation @debug @keyring @ipc @mount @obsolete @privileged @setuid";
|
||||
SystemCallFilter = "~@cpu-emulation @debug @keyring @ipc @mount @obsolete @privileged @setuid @mincore";
|
||||
};
|
||||
};
|
||||
|
||||
|
|
Loading…
Reference in a new issue