diff --git a/assets/systemd/muscl.service b/assets/systemd/muscl.service index 750c7b8..81b6680 100644 --- a/assets/systemd/muscl.service +++ b/assets/systemd/muscl.service @@ -51,6 +51,10 @@ RestrictRealtime=true RestrictSUIDSGID=true SocketBindDeny=any SystemCallArchitectures=native -SystemCallFilter=@system-service @sandbox + +SystemCallFilter=@system-service +# This is needed for landlock +# SystemCallFilter=@sandbox SystemCallFilter=~@privileged @resources + UMask=0777