diff --git a/src/portable/profile/default/service.conf b/src/portable/profile/default/service.conf index 35dfd778f2..2cb54d84c3 100644 --- a/src/portable/profile/default/service.conf +++ b/src/portable/profile/default/service.conf @@ -24,6 +24,7 @@ LockPersonality=yes MemoryDenyWriteExecute=yes RestrictRealtime=yes RestrictNamespaces=yes +DelegateNamespaces=no SystemCallFilter=@system-service SystemCallErrorNumber=EPERM SystemCallArchitectures=native diff --git a/src/portable/profile/nonetwork/service.conf b/src/portable/profile/nonetwork/service.conf index e8d2a9bb1a..29b7d6f622 100644 --- a/src/portable/profile/nonetwork/service.conf +++ b/src/portable/profile/nonetwork/service.conf @@ -22,6 +22,7 @@ LockPersonality=yes MemoryDenyWriteExecute=yes RestrictRealtime=yes RestrictNamespaces=yes +DelegateNamespaces=no SystemCallFilter=@system-service SystemCallErrorNumber=EPERM SystemCallArchitectures=native diff --git a/src/portable/profile/strict/service.conf b/src/portable/profile/strict/service.conf index aa5bcfbb08..8e7d3300e2 100644 --- a/src/portable/profile/strict/service.conf +++ b/src/portable/profile/strict/service.conf @@ -20,6 +20,7 @@ NoNewPrivileges=yes MemoryDenyWriteExecute=yes RestrictRealtime=yes RestrictNamespaces=yes +DelegateNamespaces=no SystemCallFilter=@system-service SystemCallErrorNumber=EPERM SystemCallArchitectures=native