From ce2da17c3d57b7b804e66c99e72858020ae6a058 Mon Sep 17 00:00:00 2001 From: rrr-marble Date: Thu, 21 Oct 2021 23:10:46 +0300 Subject: [PATCH] fix: syscall filter compatibility --- myip.service | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/myip.service b/myip.service index f9984d9..ff9a840 100644 --- a/myip.service +++ b/myip.service @@ -17,7 +17,8 @@ LockPersonality=true RestrictRealtime=true RestrictSUIDSGID=true RemoveIPC=true -SystemCallFilter=@network-io @basic-io @signal @file-system @process @io-event mprotect brk uname sched_getaffinity +SystemCallFilter=@network-io @basic-io @signal @file-system @process @io-event +SystemCallFilter=mprotect brk uname sched_getaffinity getrandom ioctl SystemCallFilter=~@mount ProtectSystem=strict ProtectHome=true