}
} else {
- r = mkdir_safe_label("/var/lib/systemd/timesync", 0755, uid, gid, false);
+ r = mkdir_safe_label("/var/lib/systemd/timesync", 0755, uid, gid, true);
if (r < 0)
return log_error_errno(r, "Failed to create state directory: %m");
ExecStart=!!@rootlibexecdir@/systemd-timesyncd
WatchdogSec=3min
User=systemd-timesync
+DynamicUser=yes
CapabilityBoundingSet=CAP_SYS_TIME
AmbientCapabilities=CAP_SYS_TIME
-PrivateTmp=yes
PrivateDevices=yes
-ProtectSystem=strict
ProtectHome=yes
ProtectControlGroups=yes
ProtectKernelTunables=yes