nixos/galene: set proper SystemCallFilter

This commit is contained in:
MidAutumnMoon 2022-10-24 20:19:12 +08:00
parent 29571c9c54
commit 19b481fbc6
No known key found for this signature in database
GPG Key ID: 3B9D690FD7E4664A

View File

@ -191,7 +191,7 @@ in
RestrictRealtime = true;
RestrictSUIDSGID = true;
SystemCallArchitectures = "native";
SystemCallFilter = [ "@system-service" "~@privileged" "~@resources" ];
SystemCallFilter = [ "@system-service" "~@privileged" ];
UMask = "0077";
}
];