[Unit] Description=PipeWire AGL Instrument Cluster IPC After=pipewire.socket [Service] LockPersonality=yes MemoryDenyWriteExecute=yes NoNewPrivileges=yes RestrictNamespaces=yes SystemCallArchitectures=native SystemCallFilter=@system-service Type=simple ExecStart=pipewire -c pipewire-ic-ipc.conf Restart=on-failure RuntimeDirectory=pipewire RuntimeDirectoryPreserve=yes User=pipewire Environment=PIPEWIRE_RUNTIME_DIR=%t/pipewire [Install] Also=pipewire-ic-ipc.socket WantedBy=default.target