From 22fff7274fe3d3b2c11bd49bfb417265039930df Mon Sep 17 00:00:00 2001 From: Ivan Petkov Date: Sat, 27 Jun 2026 14:24:17 -0700 Subject: [PATCH] nixos/syncoid: allow `@timer` syscalls Syncoid uses `pv` to display information about transfer speeds. During the pv bump from 1.10.5 to 1.11.0 it started using the setitimer syscall (included by `@timer`) which would segfault given that the sandbox configuration was set to block all syscalls in the `@timer` group --- nixos/modules/services/backup/syncoid.nix | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/nixos/modules/services/backup/syncoid.nix b/nixos/modules/services/backup/syncoid.nix index 4fda57e8214c..8bfb3d70a6e6 100644 --- a/nixos/modules/services/backup/syncoid.nix +++ b/nixos/modules/services/backup/syncoid.nix @@ -459,7 +459,8 @@ in "~@privileged" "~@resources" "~@setuid" - "~@timer" + # NB: pv after 1.11.0 uses timer syscalls (specifically setitimer) + # "~@timer" ]; SystemCallArchitectures = "native"; # This is for BindPaths= and BindReadOnlyPaths=