Niklas Otter Wiki
Attachments
History
Blame
View Source
Documentation
Toggle dark mode
Login
Home
A - Z
Changelog
Page Index
Linux
CHMOD
INSTALL
Linux Directory Structure
NAMEI
RCLONE
Rename LAN Connections
SAMBA
SSD
STAT
SYSTEMD
TAR
UFW
Various
An Otter Wiki
Linux
SYSTEMD
1f8f06
Commit
1f8f06
2026-08-13 15:34:35
Niklas Polke
: Add Protection Params for SYSTEMD Service
linux/systemd.md
..
@@ 47,6 47,31 @@
- `RestartSec=5` delay for automatic restart
- `Install WantedBy` tells the service what to do when `systemctl enable` is called
+
### Protection
+
| Param | Value | Effect |
+
| - | - | - |
+
| ProtectSystem | no | --- |
+
| ProtectSystem | yes | `/usr`and `/boot` are read-only |
+
| ProtectSystem | full | `/usr`and `/boot` and `/etc` are read-only |
+
| ProtectSystem | strict | almost **everything** is read-only |
+
| - | - | - |
+
| ReadWritePaths | `/var/backups` | paths with write access |
+
| ReadWritePaths | `/var/backups /var/test` | paths with write access |
+
| ReadWritePaths | `-/var/test` | paths with write access + okay if not existing at start of service |
+
| - | - | - |
+
| ReadOnlyPaths | `/home/nano/bin` | explicit read-only paths (probably not necessary with `ProtectSystem=strict`) |
+
| - | - | - |
+
| PrivateTmp | yes | cannot see foreign files in `/tmp` and `/var/tmp` |
+
| - | - | - |
+
| ProtectHome | yes | protects acces for `/home`, `/root` and `/run/user`- also no read access! |
+
| - | - | - |
+
| NoNewPrivileges | yes | no new rights through modification like `setuid` or `setgid` |
+
+
check for protection
+
```bash
+
systemd-analyze security <service>.service
+
```
+
2. Test (only needed, if not started by timer (see below))
```bash
sudo systemctl daemon-reload
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9