Files
zoneminder/misc
Isaac ConnorandClaude Opus 5 995fd54fef feat: harden zoneminder.service and pin the options ZoneMinder cannot run under
Now that the daemons reliably land in this unit rather than inheriting the web
server's namespace, the unit is worth hardening. Add the protections that do
not interfere with capture: ProtectSystem=full, ProtectClock,
ProtectControlGroups, ProtectHostname, ProtectKernelLogs, ProtectKernelModules,
ProtectKernelTunables, LockPersonality, RestrictRealtime and RestrictSUIDSGID.

Set the options that would break us explicitly rather than leaving them to a
default a distribution might override, since each fails in a way that is not
visible from the web ui:

  PrivateDevices and PrivateTmp, because zmc publishes frames in /dev/shm for a
  zms that runs under the web server, and zmaudit.pl cleans up the swap images
  zms writes under /var/tmp.

  ProcSubset and ProtectProc, because zmstats reads /proc/stat, /proc/meminfo
  and /proc/loadavg, and zmpkg.pl reads /proc/self/cgroup to decide whether
  systemd started it.

Record why NoNewPrivileges, ProtectHome and MemoryDenyWriteExecute are absent,
and warn that the mount namespace these options create hides filesystems
mounted after ZoneMinder starts.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019URmtYqza6Rzi6F7cmabSm
2026-08-14 23:37:22 -04:00
..
2018-09-26 14:47:20 -04:00
2023-05-30 20:47:05 -04:00
2023-06-07 21:39:20 +01:00
2018-12-02 09:40:15 -06:00
2013-03-17 00:45:21 +01:00
2019-05-27 13:26:29 -04:00