On 01/12/14 03:52, Micah Anderson wrote:
> If you add the option ProtectSystem=yes to the service file, then the
> daemon will not have the ability to write to /usr.
Are you sure this won't prevent a logged-in GUI user from using sudo (or
equivalent) to perform sysadmin tasks?
S