|
|
@ -204,7 +204,7 @@ in |
|
|
|
NoNewPrivileges = true; |
|
|
|
NoNewPrivileges = true; |
|
|
|
LockPersonality = true; |
|
|
|
LockPersonality = true; |
|
|
|
RestrictRealtime = true; |
|
|
|
RestrictRealtime = true; |
|
|
|
SystemCallFilter = ["@system-service" "~@priviledged" "@chown"]; |
|
|
|
SystemCallFilter = ["@system-service" "~@privileged" "@chown"]; |
|
|
|
SystemCallArchitectures = "native"; |
|
|
|
SystemCallArchitectures = "native"; |
|
|
|
RestrictAddressFamilies = "AF_INET AF_INET6"; |
|
|
|
RestrictAddressFamilies = "AF_INET AF_INET6"; |
|
|
|
}; |
|
|
|
}; |
|
|
|