diff --git a/lib/misc/service-hardened.nix b/lib/misc/service-hardened.nix index 9c54436..c9e4d4a 100644 --- a/lib/misc/service-hardened.nix +++ b/lib/misc/service-hardened.nix @@ -32,6 +32,11 @@ lib.mapAttrs (_k: lib.mkOptionDefault) { RestrictSUIDSGID = true; SystemCallArchitectures = "native"; SystemCallErrorNumber = "EPERM"; - SystemCallFilter = [ "@system-service" ]; + SystemCallFilter = [ + "" + "@system-service" + "~@resources" + "~@privileged" + ]; UMask = "0077"; }