nixos/clash: restrict tunMode further
works for me(tm)
This commit is contained in:
parent
db3baf65c0
commit
0d6792fcfd
1 changed files with 2 additions and 2 deletions
|
@ -95,8 +95,8 @@ in {
|
||||||
UMask = "0077";
|
UMask = "0077";
|
||||||
}
|
}
|
||||||
// lib.optionalAttrs cfg.tunMode {
|
// lib.optionalAttrs cfg.tunMode {
|
||||||
AmbientCapabilities = "CAP_NET_ADMIN CAP_NET_RAW";
|
AmbientCapabilities = "CAP_NET_ADMIN";
|
||||||
CapabilityBoundingSet = "CAP_NET_ADMIN CAP_NET_RAW";
|
CapabilityBoundingSet = "CAP_NET_ADMIN";
|
||||||
PrivateDevices = false;
|
PrivateDevices = false;
|
||||||
PrivateUsers = false;
|
PrivateUsers = false;
|
||||||
RestrictAddressFamilies = "AF_INET AF_INET6 AF_NETLINK";
|
RestrictAddressFamilies = "AF_INET AF_INET6 AF_NETLINK";
|
||||||
|
|
Loading…
Reference in a new issue