>>108460305
show me your program init that can do all this:
AmbientCapabilities=CAP_NET_BIND_SERVICE
NoNewPrivileges=true
ProtectSystem=full
ProtectHome=true
ProtectKernelTunables=true
ProtectKernelModules=true
ProtectControlGroups=true
MemoryDenyWriteExecute=true
SystemCallFilter=@network-io
but you won't and will continue to flail around like a stupid, jobless neetoid bitch who can't accept systemd and Poettering won, and you're an idiot AND a loser.