Commit de8b060c authored by hot burger's avatar hot burger
Browse files

nixos/conduwuit: block mistakenly allowed syscalls

Copied directly from the upstream service file instead of doing any unnecessary translating.
parent c395c185
Loading
Loading
Loading
Loading
+2 −16
Original line number Diff line number Diff line
@@ -246,22 +246,8 @@ in
        RestrictRealtime = true;
        SystemCallArchitectures = "native";
        SystemCallFilter = [
          "@system-service"
          "@resources"
          "~@clock"
          "@debug"
          "@module"
          "@mount"
          "@reboot"
          "@swap"
          "@cpu-emulation"
          "@obsolete"
          "@timer"
          "@chown"
          "@setuid"
          "@privileged"
          "@keyring"
          "@ipc"
          "@system-service @resources"
          "~@clock @debug @module @mount @reboot @swap @cpu-emulation @obsolete @timer @chown @setuid @privileged @keyring @ipc"
        ];
        SystemCallErrorNumber = "EPERM";