@ -13,7 +13,8 @@ LockPersonality=true
RestrictRealtime=true
RestrictSUIDSGID=true
RemoveIPC=true
SystemCallFilter=@system-service
SystemCallFilter=@network-io @basic-io @signal @file-system @process @io-event mprotect brk
SystemCallFilter=~@mount
ProtectSystem=strict
ProtectHome=true
RuntimeDirectory=myip