mirror of
https://github.com/ZoneMinder/zoneminder.git
synced 2026-10-02 23:45:08 -04:00
Now that the daemons reliably land in this unit rather than inheriting the web server's namespace, the unit is worth hardening. Add the protections that do not interfere with capture: ProtectSystem=full, ProtectClock, ProtectControlGroups, ProtectHostname, ProtectKernelLogs, ProtectKernelModules, ProtectKernelTunables, LockPersonality, RestrictRealtime and RestrictSUIDSGID. Set the options that would break us explicitly rather than leaving them to a default a distribution might override, since each fails in a way that is not visible from the web ui: PrivateDevices and PrivateTmp, because zmc publishes frames in /dev/shm for a zms that runs under the web server, and zmaudit.pl cleans up the swap images zms writes under /var/tmp. ProcSubset and ProtectProc, because zmstats reads /proc/stat, /proc/meminfo and /proc/loadavg, and zmpkg.pl reads /proc/self/cgroup to decide whether systemd started it. Record why NoNewPrivileges, ProtectHome and MemoryDenyWriteExecute are absent, and warn that the mount namespace these options create hides filesystems mounted after ZoneMinder starts. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019URmtYqza6Rzi6F7cmabSm