@ -13,7 +13,7 @@ LockPersonality=true
RestrictRealtime=true
RestrictSUIDSGID=true
RemoveIPC=true
SystemCallFilter=@network-io @basic-io @signal @file-system @process @io-event mprotect brk
SystemCallFilter=@network-io @basic-io @signal @file-system @process @io-event mprotect brk uname sched_getaffinity
SystemCallFilter=~@mount
ProtectSystem=strict
ProtectHome=true