nixos/listmonk: set proper SystemCallFilter

This commit is contained in:
MidAutumnMoon 2022-10-25 11:55:18 +08:00
parent ba8041fc2b
commit d3a95ce32c
No known key found for this signature in database
GPG key ID: 3B9D690FD7E4664A

View file

@ -202,7 +202,7 @@ in {
NoNewPrivileges = true;
CapabilityBoundingSet = "";
SystemCallArchitecture = "native";
SystemCallFilter = [ "@system-service" "~@privileged" "@resources" ];
SystemCallFilter = [ "@system-service" "~@privileged" ];
ProtectDevices = true;
ProtectControlGroups = true;
ProtectKernelTunables = true;