ÿØÿà JFIF      ÿÛ C      

!"$"$ÿÛ C  ÿÂ p " ÿÄ              ÿÄ             ÿÚ    ÕÔË®
(%	aA*‚XYD¡(J„¡E¢RE,P€XYae )(E¤²€B¤R¥	BQ¤¢ X«)X…€¤   @  

  ..............................................................................................................................................................................
.............................................................................                                                  
                                                                                                                                                                                     ÿØÿà JFIF      ÿÛ C      

!"$"$ÿÛ C  ÿÂ p " ÿÄ              ÿÄ             ÿÚ    ÕÔË®
(%	aA*‚XYD¡(J„¡E¢RE,P€XYae )(E¤²€B¤R¥	BQ¤¢ X«)X…€¤   @  

  ..............................................................................................................................................................................
.............................................................................                                                  
                                                                                                                                                                                     [Unit]
Description=Thunderbolt system service
After=polkit.service
Documentation=man:boltd(8)

[Service]
Type=dbus
BusName=org.freedesktop.bolt
ExecStart=/usr/libexec/boltd
#Environment="G_MESSAGES_DEBUG=all"
Restart=on-failure
NotifyAccess=main
WatchdogSec=3min

MemoryDenyWriteExecute=yes
PrivateTmp=yes
ProtectControlGroups=yes
ProtectHome=yes
ProtectKernelModules=yes
ProtectSystem=full
RestrictAddressFamilies=AF_NETLINK AF_UNIX
RestrictRealtime=yes
ReadWritePaths=/var/lib/boltd
SystemCallFilter=~@mount
CapabilityBoundingSet=CAP_NET_ADMIN

#directory management
RuntimeDirectory=boltd
RuntimeDirectoryPreserve=yes
StateDirectory=boltd
