nixos/navidrome: set proper SystemCallFilter
This commit is contained in:
parent
7415970a3e
commit
0ce08acdce
1 changed files with 1 additions and 1 deletions
|
@ -62,7 +62,7 @@ in {
|
|||
ProtectKernelModules = true;
|
||||
ProtectKernelTunables = true;
|
||||
SystemCallArchitectures = "native";
|
||||
SystemCallFilter = [ "@system-service" "~@privileged" "~@resources" ];
|
||||
SystemCallFilter = [ "@system-service" "~@privileged" ];
|
||||
RestrictRealtime = true;
|
||||
LockPersonality = true;
|
||||
MemoryDenyWriteExecute = true;
|
||||
|
|
Loading…
Reference in a new issue