nixos/yggdrasil: set proper SystemCallFilter

Changed files
+1 -1
nixos
modules
services
networking
+1 -1
nixos/modules/services/networking/yggdrasil.nix
···
RestrictNamespaces = true;
RestrictRealtime = true;
SystemCallArchitectures = "native";
-
SystemCallFilter = "~@clock @cpu-emulation @debug @keyring @module @mount @obsolete @raw-io @resources";
+
SystemCallFilter = [ "@system-service" "~@privileged @keyring" ];
} // (if (cfg.group != null) then {
Group = cfg.group;
} else {});