nixos/nats: set proper SystemCallFilter

Changed files
+1 -1
nixos
modules
services
networking
+1 -1
nixos/modules/services/networking/nats.nix
···
RestrictNamespaces = true;
RestrictRealtime = true;
RestrictSUIDSGID = true;
-
SystemCallFilter = [ "@system-service" "~@privileged" "~@resources" ];
+
SystemCallFilter = [ "@system-service" "~@privileged" ];
UMask = "0077";
}
];