Blame SOURCES/chrony-services.patch

777498
diff -up chrony-4.2/examples/chronyd.service.services chrony-4.2/examples/chronyd.service
777498
--- chrony-4.2/examples/chronyd.service.services	2021-12-16 13:17:42.000000000 +0100
777498
+++ chrony-4.2/examples/chronyd.service	2022-01-19 13:55:59.066677473 +0100
777498
@@ -32,8 +32,7 @@ ProtectKernelLogs=yes
777498
 ProtectKernelModules=yes
777498
 ProtectKernelTunables=yes
777498
 ProtectProc=invisible
777498
-ProtectSystem=strict
777498
-ReadWritePaths=/run /var/lib/chrony -/var/log
777498
+ProtectSystem=full
777498
 RestrictAddressFamilies=AF_INET AF_INET6 AF_UNIX
777498
 RestrictNamespaces=yes
777498
 RestrictSUIDSGID=yes
777498
@@ -42,7 +41,6 @@ SystemCallFilter=~@cpu-emulation @debug
777498
 
777498
 # Adjust restrictions for /usr/sbin/sendmail (mailonchange directive)
777498
 NoNewPrivileges=no
777498
-ReadWritePaths=-/var/spool
777498
 RestrictAddressFamilies=AF_NETLINK
777498
 
777498
 [Install]
777498
777498
Avoid a SELinux issue
777498
777498
diff --git a/examples/chrony-wait.service b/examples/chrony-wait.service
777498
index 72b028f2..57646950 100644
777498
--- a/examples/chrony-wait.service
777498
+++ b/examples/chrony-wait.service
777498
@@ -18,7 +18,7 @@ StandardOutput=null
777498
 
777498
 CapabilityBoundingSet=
777498
 DevicePolicy=closed
777498
-DynamicUser=yes
777498
+#DynamicUser=yes
777498
 IPAddressAllow=localhost
777498
 IPAddressDeny=any
777498
 LockPersonality=yes
777498