fix: syscall filter compatibility

master
rrr-marble 5 years ago
parent d26113d9fc
commit eaeefeab73

@ -13,7 +13,7 @@ LockPersonality=true
RestrictRealtime=true RestrictRealtime=true
RestrictSUIDSGID=true RestrictSUIDSGID=true
RemoveIPC=true RemoveIPC=true
SystemCallFilter=@network-io @basic-io @signal @file-system @process @io-event mprotect brk SystemCallFilter=@network-io @basic-io @signal @file-system @process @io-event mprotect brk uname sched_getaffinity
SystemCallFilter=~@mount SystemCallFilter=~@mount
ProtectSystem=strict ProtectSystem=strict
ProtectHome=true ProtectHome=true

Loading…
Cancel
Save