nixos/github-runner: fix capset syscall filtering

capset(2) is a single system call, not a set of multiple system calls.
This commit is contained in:
Vincent Haupert 2022-07-21 16:08:15 +02:00
parent e3a3abe560
commit 539b61ea37

View file

@ -300,7 +300,6 @@ in
UMask = "0066";
ProtectProc = "invisible";
SystemCallFilter = [
"~@capset"
"~@clock"
"~@cpu-emulation"
"~@module"
@ -308,6 +307,7 @@ in
"~@obsolete"
"~@raw-io"
"~@reboot"
"~capset"
"~setdomainname"
"~sethostname"
];