diff options
author | Sandro <sandro.jaeckel@gmail.com> | 2022-10-27 00:48:28 +0200 |
---|---|---|
committer | GitHub <noreply@github.com> | 2022-10-27 00:48:28 +0200 |
commit | dc5fa53b8342d982b84ebf24054415e8fce1c17d (patch) | |
tree | c1005979e39e5ba177b3d695cb8779c7629e5bd4 /nixos | |
parent | 6bcc077adf22b61bd12025f8c5c92d0fb39df656 (diff) | |
parent | d3a95ce32c6d3a83ed661eaf0a066a3b44e906e0 (diff) |
Merge pull request #197657 from MidAutumnMoon/go-119-services-fix
Diffstat (limited to 'nixos')
-rw-r--r-- | nixos/modules/services/mail/listmonk.nix | 2 | ||||
-rw-r--r-- | nixos/modules/services/networking/croc.nix | 2 | ||||
-rw-r--r-- | nixos/modules/services/web-apps/galene.nix | 2 |
3 files changed, 3 insertions, 3 deletions
diff --git a/nixos/modules/services/mail/listmonk.nix b/nixos/modules/services/mail/listmonk.nix index 7c298606a5478..c4ea6747196c4 100644 --- a/nixos/modules/services/mail/listmonk.nix +++ b/nixos/modules/services/mail/listmonk.nix @@ -202,7 +202,7 @@ in { NoNewPrivileges = true; CapabilityBoundingSet = ""; SystemCallArchitecture = "native"; - SystemCallFilter = [ "@system-service" "~@privileged" "@resources" ]; + SystemCallFilter = [ "@system-service" "~@privileged" ]; ProtectDevices = true; ProtectControlGroups = true; ProtectKernelTunables = true; diff --git a/nixos/modules/services/networking/croc.nix b/nixos/modules/services/networking/croc.nix index d3902611a625a..45bfd447da454 100644 --- a/nixos/modules/services/networking/croc.nix +++ b/nixos/modules/services/networking/croc.nix @@ -72,7 +72,7 @@ in RuntimeDirectoryMode = "700"; SystemCallFilter = [ "@system-service" - "~@aio" "~@keyring" "~@memlock" "~@privileged" "~@resources" "~@setuid" "~@sync" "~@timer" + "~@aio" "~@keyring" "~@memlock" "~@privileged" "~@setuid" "~@sync" "~@timer" ]; SystemCallArchitectures = "native"; SystemCallErrorNumber = "EPERM"; diff --git a/nixos/modules/services/web-apps/galene.nix b/nixos/modules/services/web-apps/galene.nix index ded104792bc08..15ef09aa0b879 100644 --- a/nixos/modules/services/web-apps/galene.nix +++ b/nixos/modules/services/web-apps/galene.nix @@ -191,7 +191,7 @@ in RestrictRealtime = true; RestrictSUIDSGID = true; SystemCallArchitectures = "native"; - SystemCallFilter = [ "@system-service" "~@privileged" "~@resources" ]; + SystemCallFilter = [ "@system-service" "~@privileged" ]; UMask = "0077"; } ]; |