4 SystemCallFilter=@default @raw-io @system-service @known
7 # binds host kodi home folder into nspawn
15 Bind=/mnt/fook/torrents
20 BindReadOnly=/dev/bus/usb
22 BindReadOnly=/dev/input
23 # libinput reads this to know about devices
24 BindReadOnly=/run/udev
25 BindReadOnly=/dev/lirc0
26 BindReadOnly=/dev/vga_arbiter
27 BindReadOnly=/lib/modules
28 # pulse need to be started in system mode with the following module and option:
29 # load-module module-native-protocol auth-authorize-anonymous
30 BindReadOnly=/run/pulse