add @resources
to syscall filter in the default systemd unit
Signed-off-by: strawberry <strawberry@puppygock.gay>
This commit is contained in:
parent
536efe2cd7
commit
5195593f55
1 changed files with 2 additions and 2 deletions
4
debian/conduwuit.service
vendored
4
debian/conduwuit.service
vendored
|
@ -36,8 +36,8 @@ RestrictNamespaces=yes
|
||||||
RestrictRealtime=yes
|
RestrictRealtime=yes
|
||||||
RestrictSUIDSGID=yes
|
RestrictSUIDSGID=yes
|
||||||
SystemCallArchitectures=native
|
SystemCallArchitectures=native
|
||||||
SystemCallFilter=@system-service
|
SystemCallFilter=@system-service @resources
|
||||||
SystemCallFilter=~@clock @debug @module @mount @reboot @swap @cpu-emulation @obsolete @timer @chown @setuid @resources @privileged @keyring @ipc
|
SystemCallFilter=~@clock @debug @module @mount @reboot @swap @cpu-emulation @obsolete @timer @chown @setuid @privileged @keyring @ipc
|
||||||
SystemCallErrorNumber=EPERM
|
SystemCallErrorNumber=EPERM
|
||||||
StateDirectory=matrix-conduit
|
StateDirectory=matrix-conduit
|
||||||
|
|
||||||
|
|
Loading…
Add table
Reference in a new issue