diff --git a/myip.service b/myip.service index f9984d9..ff9a840 100644 --- a/myip.service +++ b/myip.service @@ -17,7 +17,8 @@ LockPersonality=true RestrictRealtime=true RestrictSUIDSGID=true RemoveIPC=true -SystemCallFilter=@network-io @basic-io @signal @file-system @process @io-event mprotect brk uname sched_getaffinity +SystemCallFilter=@network-io @basic-io @signal @file-system @process @io-event +SystemCallFilter=mprotect brk uname sched_getaffinity getrandom ioctl SystemCallFilter=~@mount ProtectSystem=strict ProtectHome=true