Skip to content

Changed: harden systemd unit and fix DynamicUser conflict#412

Merged
mnot merged 1 commit into
mainfrom
claude/beautiful-varahamihira-28847b
May 16, 2026
Merged

Changed: harden systemd unit and fix DynamicUser conflict#412
mnot merged 1 commit into
mainfrom
claude/beautiful-varahamihira-28847b

Conversation

@mnot
Copy link
Copy Markdown
Owner

@mnot mnot commented May 16, 2026

  • Remove static User=/Group= which are ignored under DynamicUser=true.
  • Fix Description (quotes were not stripped).
  • Add ProtectKernelLogs, ProcSubset=pid, RestrictSUIDSGID, RestrictRealtime, KeyringMode=private, and UMask=0077.

- Remove static User=/Group= which are ignored under DynamicUser=true.
- Fix Description (quotes were not stripped).
- Add ProtectKernelLogs, ProcSubset=pid, RestrictSUIDSGID,
  RestrictRealtime, KeyringMode=private, and UMask=0077.
@mnot mnot merged commit 58bf189 into main May 16, 2026
11 of 12 checks passed
@mnot mnot deleted the claude/beautiful-varahamihira-28847b branch May 16, 2026 03:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant