Merge pull request #182342 from veehaitch/github-runner-capset

nixos/github-runner: fix capset syscall filtering
This commit is contained in:
Winter 2022-07-21 11:26:34 -04:00 committed by GitHub
commit 2922becf6d
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -300,7 +300,6 @@ in
UMask = "0066"; UMask = "0066";
ProtectProc = "invisible"; ProtectProc = "invisible";
SystemCallFilter = [ SystemCallFilter = [
"~@capset"
"~@clock" "~@clock"
"~@cpu-emulation" "~@cpu-emulation"
"~@module" "~@module"
@ -308,6 +307,7 @@ in
"~@obsolete" "~@obsolete"
"~@raw-io" "~@raw-io"
"~@reboot" "~@reboot"
"~capset"
"~setdomainname" "~setdomainname"
"~sethostname" "~sethostname"
]; ];