Unverified Commit 16524a25 authored by Martin Weinelt's avatar Martin Weinelt Committed by GitHub
Browse files

nixos/logrotate: reorder setuid syscall group (#345487)

parents f0ab2015 4ca03e3a
Loading
Loading
Loading
Loading
+3 −2
Original line number Diff line number Diff line
@@ -261,6 +261,7 @@ in
        CapabilityBoundingSet = [
          "CAP_CHOWN"
          "CAP_DAC_OVERRIDE"
          "CAP_KILL"
          "CAP_SETUID"
          "CAP_SETGID"
        ];
@@ -285,9 +286,9 @@ in
        RestrictSUIDSGID = false; # can create sgid directories
        SystemCallArchitectures = "native";
        SystemCallFilter = [
          "@system-service @setuid"
          "@system-service"
          "~@privileged @resources"
          "@chown"
          "@chown @setuid"
        ];
        UMask = "0027";
      } // lib.optionalAttrs (!cfg.allowNetworking) {