blob: f273dd0503fdbce35162ac050f2d2f9035293143 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
|
[Unit]
Description=Enlightened Sound Daemon
Documentation=man:esd(1)
[Service]
Environment=ESD_DEBUG=1
ExecStart=/usr/bin/esd
Restart=on-failure
# esd opens FIFOs on /tmp
PrivateTmp=false
# Security options
ProtectSystem=full
ProtectHome=read-only
ProtectClock=true
ProtectKernelTunables=true
ProtectControlGroups=true
ProtectKernelModules=true
LockPersonality=yes
MemoryDenyWriteExecute=yes
NoNewPrivileges=yes
RestrictNamespaces=yes
SystemCallArchitectures=native
[Install]
WantedBy=multi-user.target
|