Loading nixos/modules/services/mail/listmonk.nix +1 −1 Original line number Diff line number Diff line Loading @@ -202,7 +202,7 @@ in { NoNewPrivileges = true; CapabilityBoundingSet = ""; SystemCallArchitecture = "native"; SystemCallFilter = [ "@system-service" "~@privileged" "@resources" ]; SystemCallFilter = [ "@system-service" "~@privileged" ]; ProtectDevices = true; ProtectControlGroups = true; ProtectKernelTunables = true; Loading nixos/modules/services/networking/croc.nix +1 −1 Original line number Diff line number Diff line Loading @@ -72,7 +72,7 @@ in RuntimeDirectoryMode = "700"; SystemCallFilter = [ "@system-service" "~@aio" "~@keyring" "~@memlock" "~@privileged" "~@resources" "~@setuid" "~@sync" "~@timer" "~@aio" "~@keyring" "~@memlock" "~@privileged" "~@setuid" "~@sync" "~@timer" ]; SystemCallArchitectures = "native"; SystemCallErrorNumber = "EPERM"; Loading nixos/modules/services/web-apps/galene.nix +1 −1 Original line number Diff line number Diff line Loading @@ -191,7 +191,7 @@ in RestrictRealtime = true; RestrictSUIDSGID = true; SystemCallArchitectures = "native"; SystemCallFilter = [ "@system-service" "~@privileged" "~@resources" ]; SystemCallFilter = [ "@system-service" "~@privileged" ]; UMask = "0077"; } ]; Loading Loading
nixos/modules/services/mail/listmonk.nix +1 −1 Original line number Diff line number Diff line Loading @@ -202,7 +202,7 @@ in { NoNewPrivileges = true; CapabilityBoundingSet = ""; SystemCallArchitecture = "native"; SystemCallFilter = [ "@system-service" "~@privileged" "@resources" ]; SystemCallFilter = [ "@system-service" "~@privileged" ]; ProtectDevices = true; ProtectControlGroups = true; ProtectKernelTunables = true; Loading
nixos/modules/services/networking/croc.nix +1 −1 Original line number Diff line number Diff line Loading @@ -72,7 +72,7 @@ in RuntimeDirectoryMode = "700"; SystemCallFilter = [ "@system-service" "~@aio" "~@keyring" "~@memlock" "~@privileged" "~@resources" "~@setuid" "~@sync" "~@timer" "~@aio" "~@keyring" "~@memlock" "~@privileged" "~@setuid" "~@sync" "~@timer" ]; SystemCallArchitectures = "native"; SystemCallErrorNumber = "EPERM"; Loading
nixos/modules/services/web-apps/galene.nix +1 −1 Original line number Diff line number Diff line Loading @@ -191,7 +191,7 @@ in RestrictRealtime = true; RestrictSUIDSGID = true; SystemCallArchitectures = "native"; SystemCallFilter = [ "@system-service" "~@privileged" "~@resources" ]; SystemCallFilter = [ "@system-service" "~@privileged" ]; UMask = "0077"; } ]; Loading