| 1234567891011121314151617181920212223242526272829 | [Unit]Description = Anonymizing overlay network for TCPAfter = syslog.target network.target nss-lookup.target[Service]Type = notifyNotifyAccess = allExecStartPre = @BINDIR@/tor -f @CONFDIR@/torrc --verify-configExecStart = @BINDIR@/tor -f @CONFDIR@/torrcExecReload = /bin/kill -HUP ${MAINPID}KillSignal = SIGINTTimeoutSec = 30Restart = on-failureWatchdogSec = 1mLimitNOFILE = 32768# HardeningPrivateTmp = yesPrivateDevices = yesProtectHome = yesProtectSystem = fullReadOnlyDirectories = /ReadWriteDirectories = -@LOCALSTATEDIR@/lib/torReadWriteDirectories = -@LOCALSTATEDIR@/log/torNoNewPrivileges = yesCapabilityBoundingSet = CAP_SETUID CAP_SETGID CAP_NET_BIND_SERVICE[Install]WantedBy = multi-user.target
 |