|
|
|
@ -17,7 +17,8 @@ LockPersonality=true
|
|
|
|
RestrictRealtime=true
|
|
|
|
RestrictRealtime=true
|
|
|
|
RestrictSUIDSGID=true
|
|
|
|
RestrictSUIDSGID=true
|
|
|
|
RemoveIPC=true
|
|
|
|
RemoveIPC=true
|
|
|
|
SystemCallFilter=@network-io @basic-io @signal @file-system @process @io-event mprotect brk uname sched_getaffinity
|
|
|
|
SystemCallFilter=@network-io @basic-io @signal @file-system @process @io-event
|
|
|
|
|
|
|
|
SystemCallFilter=mprotect brk uname sched_getaffinity getrandom ioctl
|
|
|
|
SystemCallFilter=~@mount
|
|
|
|
SystemCallFilter=~@mount
|
|
|
|
ProtectSystem=strict
|
|
|
|
ProtectSystem=strict
|
|
|
|
ProtectHome=true
|
|
|
|
ProtectHome=true
|
|
|
|
|