summary refs log tree commit diff
path: root/nixos/modules/services/networking
diff options
context:
space:
mode:
authorMidAutumnMoon <me@418.im>2022-10-25 16:47:46 +0800
committerMidAutumnMoon <me@418.im>2022-10-25 16:47:46 +0800
commit9b8fd74d68fca9eace442379fc74b80bbab894c1 (patch)
treee8d4640fb9eac6859a472cf1078d1d49b47df8ce /nixos/modules/services/networking
parentafb8d0e5a62c6018c4cd3545c76e672cec6ccabb (diff)
nixos/nats: set proper SystemCallFilter
Diffstat (limited to 'nixos/modules/services/networking')
-rw-r--r--nixos/modules/services/networking/nats.nix2
1 files changed, 1 insertions, 1 deletions
diff --git a/nixos/modules/services/networking/nats.nix b/nixos/modules/services/networking/nats.nix
index dd732d2a9fca4..6c21e21b5cb88 100644
--- a/nixos/modules/services/networking/nats.nix
+++ b/nixos/modules/services/networking/nats.nix
@@ -137,7 +137,7 @@ in {
           RestrictNamespaces = true;
           RestrictRealtime = true;
           RestrictSUIDSGID = true;
-          SystemCallFilter = [ "@system-service" "~@privileged" "~@resources" ];
+          SystemCallFilter = [ "@system-service" "~@privileged" ];
           UMask = "0077";
         }
       ];