[systemd-devel] Normal user can ask status of services

Dave Howorth systemd at howorth.org.uk
Sat Aug 26 15:35:25 UTC 2023


On Sat, 26 Aug 2023 16:17:46 +0300
Andrei Borzenkov <arvidjaar at gmail.com> wrote:
> On 26.08.2023 15:46, Michael Biebl wrote:
> > 
> > Reading system logs is a privileged operation.
> 
> It is not about reading logs but about being able to "systemctl
> status some-system-unit"
> 
> > You can grant this privilege to individual users by adding them to
> > the systemd-journal (or adm) group.
> 
> The question was how to prevent normal users from seeing system unit
> status.

TBF, it wasn't really clear (to me at least) what the question was
about. Either what you surmised, or what Michael surmised or maybe
about which Debian releases have cron installed by default? I certainly
couldn't work it out.


More information about the systemd-devel mailing list