Merge pull request #122825 from Izorkin/update-duplicates-systemcallfilters

treewide: remove duplicates SystemCallFilters

Changed files
+6 -13
nixos
modules
services
databases
misc
network-filesystems
networking
web-apps
web-servers
nginx
+1 -1
nixos/modules/services/databases/redis.nix
···
PrivateMounts = true;
# System Call Filtering
SystemCallArchitectures = "native";
-
SystemCallFilter = "~@clock @cpu-emulation @debug @keyring @memlock @module @mount @obsolete @privileged @raw-io @reboot @resources @setuid @swap";
+
SystemCallFilter = "~@cpu-emulation @debug @keyring @memlock @mount @obsolete @privileged @resources @setuid";
};
};
};
+1 -3
nixos/modules/services/misc/jellyfin.nix
···
SystemCallErrorNumber = "EPERM";
SystemCallFilter = [
"@system-service"
-
-
"~@chown" "~@cpu-emulation" "~@debug" "~@keyring" "~@memlock" "~@module"
-
"~@obsolete" "~@privileged" "~@setuid"
+
"~@cpu-emulation" "~@debug" "~@keyring" "~@memlock" "~@obsolete" "~@privileged" "~@setuid"
];
};
};
+1 -1
nixos/modules/services/network-filesystems/samba-wsdd.nix
···
PrivateMounts = true;
# System Call Filtering
SystemCallArchitectures = "native";
-
SystemCallFilter = "~@clock @cpu-emulation @debug @module @mount @obsolete @privileged @raw-io @reboot @resources @swap";
+
SystemCallFilter = "~@cpu-emulation @debug @mount @obsolete @privileged @resources";
};
};
};
+1 -3
nixos/modules/services/networking/croc.nix
···
RuntimeDirectoryMode = "700";
SystemCallFilter = [
"@system-service"
-
"~@aio" "~@chown" "~@keyring" "~@memlock"
-
"~@privileged" "~@resources" "~@setuid"
-
"~@sync" "~@timer"
+
"~@aio" "~@keyring" "~@memlock" "~@privileged" "~@resources" "~@setuid" "~@sync" "~@timer"
];
SystemCallArchitectures = "native";
SystemCallErrorNumber = "EPERM";
+1 -4
nixos/modules/services/web-apps/shiori.nix
···
SystemCallErrorNumber = "EPERM";
SystemCallFilter = [
"@system-service"
-
-
"~@chown" "~@cpu-emulation" "~@debug" "~@keyring" "~@memlock"
-
"~@module" "~@obsolete" "~@privileged" "~@raw-io"
-
"~@resources" "~@setuid"
+
"~@cpu-emulation" "~@debug" "~@keyring" "~@memlock" "~@obsolete" "~@privileged" "~@resources" "~@setuid"
];
};
};
+1 -1
nixos/modules/services/web-servers/nginx/default.nix
···
PrivateMounts = true;
# System Call Filtering
SystemCallArchitectures = "native";
-
SystemCallFilter = "~@chown @cpu-emulation @debug @keyring @ipc @module @mount @obsolete @privileged @raw-io @reboot @setuid @swap";
+
SystemCallFilter = "~@cpu-emulation @debug @keyring @ipc @mount @obsolete @privileged @setuid";
};
};