nixos/yggdrasil: set proper SystemCallFilter

This commit is contained in:
MidAutumnMoon 2022-10-25 16:09:31 +08:00
parent ae025da558
commit 7742cd543d
No known key found for this signature in database
GPG key ID: 3B9D690FD7E4664A

View file

@ -180,7 +180,7 @@ in {
RestrictNamespaces = true;
RestrictRealtime = true;
SystemCallArchitectures = "native";
SystemCallFilter = "~@clock @cpu-emulation @debug @keyring @module @mount @obsolete @raw-io @resources";
SystemCallFilter = [ "@system-service" "~@privileged @keyring" ];
} // (if (cfg.group != null) then {
Group = cfg.group;
} else {});