diff --git a/scripts/packaging/polkadot.service b/scripts/packaging/polkadot.service index 6d6a9f6f6629..7fb549c97f8b 100644 --- a/scripts/packaging/polkadot.service +++ b/scripts/packaging/polkadot.service @@ -29,6 +29,7 @@ RestrictNamespaces=true RestrictSUIDSGID=true SystemCallArchitectures=native SystemCallFilter=@system-service +SystemCallFilter=landlock_add_rule landlock_create_ruleset landlock_restrict_self seccomp SystemCallFilter=~@clock @module @mount @reboot @swap @privileged UMask=0027