[Service] ConfigurationDirectory=matrix-synapse LockPersonality=yes LogsDirectory=matrix-synapse NoNewPrivileges=yes PrivateDevices=yes PrivateTmp=yes ProtectControlGroups=yes ProtectHome=yes ProtectKernelLogs=yes ProtectKernelModules=yes ProtectKernelTunables=yes ProtectSystem=strict RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6 RestrictRealtime=yes StateDirectory=matrix-synapse SystemCallArchitectures=native