nixos/navidrome: set proper SystemCallFilter

This commit is contained in:
MidAutumnMoon 2022-10-24 11:02:42 +08:00 committed by zowoq
parent 7415970a3e
commit 0ce08acdce

View file

@ -62,7 +62,7 @@ in {
ProtectKernelModules = true;
ProtectKernelTunables = true;
SystemCallArchitectures = "native";
SystemCallFilter = [ "@system-service" "~@privileged" "~@resources" ];
SystemCallFilter = [ "@system-service" "~@privileged" ];
RestrictRealtime = true;
LockPersonality = true;
MemoryDenyWriteExecute = true;