nixos/snowflake-proxy: set proper SystemCallFilter

This commit is contained in:
MidAutumnMoon 2022-10-25 15:41:54 +08:00
parent 8e22463268
commit bd8413e8e1
No known key found for this signature in database
GPG Key ID: 3B9D690FD7E4664A

View File

@ -71,7 +71,7 @@ in
RestrictNamespaces = true;
RestrictRealtime = true;
SystemCallArchitectures = "native";
SystemCallFilter = "~@clock @cpu-emulation @debug @mount @obsolete @reboot @swap @privileged @resources";
SystemCallFilter = [ "@system-service" "~@privileged" ];
UMask = "0077";
};
};