Commit 1f8f06

2026-08-13 15:34:35 Niklas Polke: Add Protection Params for SYSTEMD Service
linux/systemd.md ..
@@ 47,6 47,31 @@
- `RestartSec=5` delay for automatic restart
- `Install WantedBy` tells the service what to do when `systemctl enable` is called
+ ### Protection
+ | Param | Value | Effect |
+ | - | - | - |
+ | ProtectSystem | no | --- |
+ | ProtectSystem | yes | `/usr`and `/boot` are read-only |
+ | ProtectSystem | full | `/usr`and `/boot` and `/etc` are read-only |
+ | ProtectSystem | strict | almost **everything** is read-only |
+ | - | - | - |
+ | ReadWritePaths | `/var/backups` | paths with write access |
+ | ReadWritePaths | `/var/backups /var/test` | paths with write access |
+ | ReadWritePaths | `-/var/test` | paths with write access + okay if not existing at start of service |
+ | - | - | - |
+ | ReadOnlyPaths | `/home/nano/bin` | explicit read-only paths (probably not necessary with `ProtectSystem=strict`) |
+ | - | - | - |
+ | PrivateTmp | yes | cannot see foreign files in `/tmp` and `/var/tmp` |
+ | - | - | - |
+ | ProtectHome | yes | protects acces for `/home`, `/root` and `/run/user`- also no read access! |
+ | - | - | - |
+ | NoNewPrivileges | yes | no new rights through modification like `setuid` or `setgid` |
+
+ check for protection
+ ```bash
+ systemd-analyze security <service>.service
+ ```
+
2. Test (only needed, if not started by timer (see below))
```bash
sudo systemctl daemon-reload
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9