| 12345678910111213141516171819202122232425262728 | [Unit]Description = Anonymizing overlay network for TCPAfter = syslog.target network.target nss-lookup.target[Service]Type = simpleExecStartPre = @BINDIR@/tor -f @CONFDIR@/torrc --verify-config# A torrc that has "RunAsDaemon 1" won't work with the "simple" service type;# let's explicitly override it.ExecStart = @BINDIR@/tor -f @CONFDIR@/torrc --RunAsDaemon 0ExecReload = /bin/kill -HUP ${MAINPID}KillSignal = SIGINTTimeoutSec = 30Restart = on-failureLimitNOFILE = 32768# HardeningPrivateTmp = yesDeviceAllow = /dev/null rwDeviceAllow = /dev/urandom rInaccessibleDirectories = /homeReadOnlyDirectories = /ReadWriteDirectories = @LOCALSTATEDIR@/lib/torReadWriteDirectories = @LOCALSTATEDIR@/log/torNoNewPrivileges = yes[Install]WantedBy = multi-user.target
 |