From ec93956a891122be3de38d5adabe96ceb4fea952 Mon Sep 17 00:00:00 2001 From: Alexey Avramov Date: Wed, 2 Oct 2019 01:27:37 +0900 Subject: [PATCH] update nohang.service --- nohang/nohang.service.in | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/nohang/nohang.service.in b/nohang/nohang.service.in index c4284ac..4ab1605 100644 --- a/nohang/nohang.service.in +++ b/nohang/nohang.service.in @@ -14,8 +14,8 @@ OOMScoreAdjust=-10 RestrictRealtime=yes MemoryDenyWriteExecute=yes ProtectKernelModules=true -SystemCallFilter=~@mount ~@clock ~@reboot ~@resources ~@setuid ~@swap SystemCallArchitectures=native +SystemCallFilter=~@mount ReadOnlyPaths=/ ReadWritePaths=/tmp /var /run /dev/shm