diff options
Diffstat (limited to 'nixpkgs/nixos/modules/services/networking/dnscrypt-proxy2.nix')
-rw-r--r-- | nixpkgs/nixos/modules/services/networking/dnscrypt-proxy2.nix | 8 |
1 files changed, 7 insertions, 1 deletions
diff --git a/nixpkgs/nixos/modules/services/networking/dnscrypt-proxy2.nix b/nixpkgs/nixos/modules/services/networking/dnscrypt-proxy2.nix index ff8a2ab30774..afc2a6d1c757 100644 --- a/nixpkgs/nixos/modules/services/networking/dnscrypt-proxy2.nix +++ b/nixpkgs/nixos/modules/services/networking/dnscrypt-proxy2.nix @@ -87,6 +87,7 @@ in NoNewPrivileges = true; NonBlocking = true; PrivateDevices = true; + ProtectClock = true; ProtectControlGroups = true; ProtectHome = true; ProtectHostname = true; @@ -107,8 +108,13 @@ in SystemCallFilter = [ "@system-service" "@chown" + "~@aio" + "~@keyring" + "~@memlock" "~@resources" - "@privileged" + "~@setuid" + "~@sync" + "~@timer" ]; }; }; |