Would dropping SystemCallArchitectures=native simplify syscall filter?
SystemCallArchitectures=native