nixos/prometheus-smartctl: set proper SystemCallFilter

Changed files
+1 -4
nixos
modules
services
monitoring
prometheus
exporters
+1 -4
nixos/modules/services/monitoring/prometheus/exporters/smartctl.nix
···
ProtectProc = "invisible";
ProcSubset = "pid";
SupplementaryGroups = [ "disk" ];
-
SystemCallFilter = [
-
"@system-service"
-
"~@privileged @resources"
-
];
};
};
}
···
ProtectProc = "invisible";
ProcSubset = "pid";
SupplementaryGroups = [ "disk" ];
+
SystemCallFilter = [ "@system-service" "~@privileged" ];
};
};
}