2 # Never accessible to any services
5 # By default inaccessible, may be overriden with BindPaths/BindReadOnlyPaths
6 TemporaryFileSystem=/home:ro
12 ProtectKernelTunables=yes
13 ProtectKernelModules=yes
14 ProtectControlGroups=yes
18 RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6
20 RestrictNamespaces=yes
21 MemoryDenyWriteExecute=yes
24 CapabilityBoundingSet=~CAP_SYS_ADMIN
25 SystemCallFilter=@system-service
26 SystemCallErrorNumber=EPERM
27 SystemCallArchitectures=native