nixos/gitea: update SystemCallFilter

Izorkin 59dbe319 239a93f2

Changed files
+1 -1
nixos
modules
services
networking
+1 -1
nixos/modules/services/networking/ntp/chrony.nix
···
PrivateMounts = true;
# System Call Filtering
SystemCallArchitectures = "native";
-
SystemCallFilter = [ "~@cpu-emulation @debug @keyring @mount @obsolete @privileged @resources" "@clock" "@setuid" "capset" "chown" ];
+
SystemCallFilter = [ "~@cpu-emulation @debug @keyring @mount @obsolete @privileged @resources" "@clock" "@setuid" "capset" "chown" ] ++ lib.optional pkgs.stdenv.hostPlatform.isAarch64 "fchownat";
};
};
};