@pid_eins is it expected a service can do mlock() when it has just allow-listed SystemCallFilter=@system-service? I couldn't find any docs on what caps system-service actually maps to.
We're trying to move from denying-listing caps to allow-listing in #fwupd. Thanks!