nixos/clash: restrict tunMode further
works for me(tm)
This commit is contained in:
parent
db3baf65c0
commit
0d6792fcfd
1 changed files with 2 additions and 2 deletions
|
@ -95,8 +95,8 @@ in {
|
|||
UMask = "0077";
|
||||
}
|
||||
// lib.optionalAttrs cfg.tunMode {
|
||||
AmbientCapabilities = "CAP_NET_ADMIN CAP_NET_RAW";
|
||||
CapabilityBoundingSet = "CAP_NET_ADMIN CAP_NET_RAW";
|
||||
AmbientCapabilities = "CAP_NET_ADMIN";
|
||||
CapabilityBoundingSet = "CAP_NET_ADMIN";
|
||||
PrivateDevices = false;
|
||||
PrivateUsers = false;
|
||||
RestrictAddressFamilies = "AF_INET AF_INET6 AF_NETLINK";
|
||||
|
|
Loading…
Reference in a new issue