diff --git a/lib/misc/service-hardened.nix b/lib/misc/service-hardened.nix index 0d021c6..9c54436 100644 --- a/lib/misc/service-hardened.nix +++ b/lib/misc/service-hardened.nix @@ -33,4 +33,5 @@ lib.mapAttrs (_k: lib.mkOptionDefault) { SystemCallArchitectures = "native"; SystemCallErrorNumber = "EPERM"; SystemCallFilter = [ "@system-service" ]; + UMask = "0077"; }