1 2 3 4 5 6 7 8 9 10
[Unit] Description=Test for SystemCallFilter [Service] ExecStart=/bin/echo "Foo bar" Type=oneshot SystemCallFilter=~read write open execve ioperm SystemCallFilter=ioctl SystemCallFilter=read write open execve SystemCallFilter=~ioperm