diff --git a/myip.service b/myip.service index 332df3a..78e16c0 100644 --- a/myip.service +++ b/myip.service @@ -13,7 +13,8 @@ LockPersonality=true RestrictRealtime=true RestrictSUIDSGID=true RemoveIPC=true -SystemCallFilter=@system-service +SystemCallFilter=@network-io @basic-io @signal @file-system @process @io-event mprotect brk +SystemCallFilter=~@mount ProtectSystem=strict ProtectHome=true RuntimeDirectory=myip