[Unit]Description=Test for SystemCallFilter in system mode with User set (daemon)[Service]ExecStart=/bin/sh -c 'echo "Foo bar"'Type=oneshotUser=daemonSystemCallFilter=~read write open execve iopermSystemCallFilter=ioctlSystemCallFilter=read write open execveSystemCallFilter=~ioperm