about summary refs log tree commit diff
path: root/dist
diff options
context:
space:
mode:
authorYurii Izorkin <izorkin@elven.pw>2021-04-27 21:34:53 +0300
committerGitHub <noreply@github.com>2021-04-27 20:34:53 +0200
commit7da104eb11d3df12f89489a7d728b8b5df8425a8 (patch)
treeb82919604338078ae8cb33742874344c0435c080 /dist
parent0bc909687af6d5176318fc82db8b497dfff040e1 (diff)
templates/systemd/mastodon: optimize SystemCallFilters (#16127)
Diffstat (limited to 'dist')
-rw-r--r--dist/mastodon-sidekiq.service2
-rw-r--r--dist/mastodon-web.service2
2 files changed, 2 insertions, 2 deletions
diff --git a/dist/mastodon-sidekiq.service b/dist/mastodon-sidekiq.service
index e171475b5..9dd21b8a0 100644
--- a/dist/mastodon-sidekiq.service
+++ b/dist/mastodon-sidekiq.service
@@ -38,7 +38,7 @@ PrivateMounts=true
 ProtectClock=true
 # System Call Filtering
 SystemCallArchitectures=native
-SystemCallFilter=~@clock @cpu-emulation @debug @keyring @module @mount @obsolete @privileged @raw-io @reboot @resources @setuid @swap
+SystemCallFilter=~@clock @cpu-emulation @debug @keyring @module @mount @obsolete @raw-io @reboot @setuid @swap
 
 [Install]
 WantedBy=multi-user.target
diff --git a/dist/mastodon-web.service b/dist/mastodon-web.service
index fd9e28770..c106a4860 100644
--- a/dist/mastodon-web.service
+++ b/dist/mastodon-web.service
@@ -38,7 +38,7 @@ PrivateMounts=true
 ProtectClock=true
 # System Call Filtering
 SystemCallArchitectures=native
-SystemCallFilter=~@clock @cpu-emulation @debug @keyring @module @mount @obsolete @privileged @raw-io @reboot @resources @setuid @swap
+SystemCallFilter=~@clock @cpu-emulation @debug @keyring @module @mount @obsolete @raw-io @reboot @resources @setuid @swap
 
 [Install]
 WantedBy=multi-user.target