aboutsummaryrefslogtreecommitdiffstats
path: root/modules/by-name/sh
diff options
context:
space:
mode:
authorBenedikt Peetz <benedikt.peetz@b-peetz.de>2025-04-25 22:21:10 +0200
committerBenedikt Peetz <benedikt.peetz@b-peetz.de>2025-04-25 22:21:10 +0200
commitd029ca2d552a38961d6f4b9e642062cb05403866 (patch)
tree259c211d1bd9a1321d5bc4a3ab2155bb7b5013ae /modules/by-name/sh
parenttests/sharkey-image: Rename to `sharkey-cpu` (diff)
downloadnixos-server-d029ca2d552a38961d6f4b9e642062cb05403866.zip
modules/sharkey: Add required `@chown` syscall group to allow list
The `~@priviledged` needed to go, as `@chown` is part of this group.
Diffstat (limited to 'modules/by-name/sh')
-rw-r--r--modules/by-name/sh/sharkey/module.nix2
1 files changed, 1 insertions, 1 deletions
diff --git a/modules/by-name/sh/sharkey/module.nix b/modules/by-name/sh/sharkey/module.nix
index 29bae51..2b50cf0 100644
--- a/modules/by-name/sh/sharkey/module.nix
+++ b/modules/by-name/sh/sharkey/module.nix
@@ -267,7 +267,7 @@ in {
SystemCallArchitectures = "native";
SystemCallFilter = [
"@system-service"
- "~@privileged"
+ "@chown"
"~@mount"
];
UMask = "0077";