nixos/geoipupdate: set proper SystemCallFilter

Changed files
+1 -1
nixos
modules
services
+1 -1
nixos/modules/services/misc/geoipupdate.nix
···
ProtectKernelTunables = true;
ProtectProc = "invisible";
ProcSubset = "pid";
-
SystemCallFilter = [ "@system-service" "~@privileged" "~@resources" ];
+
SystemCallFilter = [ "@system-service" "~@privileged" ];
RestrictAddressFamilies = [ "AF_INET" "AF_INET6" ];
RestrictRealtime = true;
RestrictNamespaces = true;