A common and reliable pattern in service unit files is thus:
NoNewPrivileges=yes
PrivateTmp=yes
PrivateDevices=yes
DevicePolicy=closed
ProtectSystem=strict
| //!HOOK MAINPRESUB | |
| //!BIND HOOKED | |
| //!DESC un360 | |
| #define M_PI 3.1415926535897932384626433832795 | |
| const float fov = M_PI/2; // [0 to M_PI] horizontal field of view, range is exclusive | |
| const float yaw = M_PI*1; // [any float] polar angle, one full revolution is 2*M_PI | |
| const float pitch = M_PI*0; // [any float] vertical tilt, positive is up | |
| const float roll = M_PI*0; // [any float] view rotation, positive is clockwise |
| from struct import unpack as up | |
| import sys, os | |
| dirs, files = None, None | |
| def read_at(fp, off, len): | |
| fp.seek(off) | |
| return fp.read(len) | |
| def read_u8(fp, off): |
| if (typeof exports === 'undefined') exports = {} | |
| function timer (repeats, func, delay) { | |
| var args = Array.prototype.slice.call(arguments, 2, -1) | |
| args.unshift(this) | |
| var boundFunc = func.bind.apply(func, args) | |
| var operation = $.NSBlockOperation.blockOperationWithBlock(boundFunc) | |
| var timer = $.NSTimer.timerWithTimeIntervalTargetSelectorUserInfoRepeats( | |
| delay / 1000, operation, 'main', null, repeats | |
| ) |
| -- betterchapters.lua | |
| -- seeks forward until a black screen appears. | |
| -- default keybinding: b | |
| -- Keybind names: skip_scene | |
| script_name = mp.get_script_name() | |
| detect_label = string.format("%s-detect", script_name) | |
| detecting = false | |
| threshold = 0.9 | |
| detection_span = 0.05 | |
| negation = false |
| # /etc/systemd/system/docker.service.d/docker-nftables.conf | |
| # disable iptables in docker, allowing nftables to do work | |
| [Service] | |
| ExecStart= | |
| ExecStart=/usr/bin/docker daemon -H fd:// --iptables=false |
| #!/usr/bin/env tclkit | |
| # | |
| # Bitrock unpacking script | |
| # | |
| # This script must be executed using 32-bit tclkit | |
| # | |
| # Author : mickael9 <mickael9 at gmail dot com> | |
| # | |
| # Latest version can be found at: | |
| # https://gist.github.com/mickael9/0b902da7c13207d1b86e |
| ################## | |
| # Privacy Settings | |
| ################## | |
| # Privacy: Let apps use my advertising ID: Disable | |
| Set-ItemProperty -Path HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\AdvertisingInfo -Name Enabled -Type DWord -Value 0 | |
| # To Restore: | |
| #Set-ItemProperty -Path HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\AdvertisingInfo -Name Enabled -Type DWord -Value 1 | |
| # Privacy: SmartScreen Filter for Store Apps: Disable | |
| Set-ItemProperty -Path HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\AppHost -Name EnableWebContentEvaluation -Type DWord -Value 0 |
| #!/usr/bin/env python3 | |
| import sys | |
| import getopt | |
| from PIL import Image | |
| xterm256colors = [ # http://pln.jonas.me/xterm-colors | |
| (0, (0x00, 0x00, 0x00)), # SYSTEM | |
| (1, (0x80, 0x00, 0x00)), # SYSTEM | |
| (2, (0x00, 0x80, 0x00)), # SYSTEM | |
| (3, (0x80, 0x80, 0x00)), # SYSTEM |
| ok = (ok) -> console.log if ok then 'ok' else 'FAIL' | |
| FnError = (message) -> | |
| @name = 'FnError' | |
| @message = message | |
| @stack = (new Error).stack | |
| FnError:: = new Error |