mini-httpd (1.30-10) unstable; urgency=medium The updated systemd service file introduces hardening features which aim to increase security but might require minor tweaking to existing setups. For example, the ProtectSystem=full directive mounts the /usr/, /etc/ and the boot loader directories (/boot and /efi) read-only for processes invoked by this unit. Thus, CGI scripts that rely on writing to those directories will fail to do so. Subprocesses will no longer be able to read kernel logs, change the system clock, change the hostname or load kernel modules. A HTTP server should not perform these actions anyway, so we keep these hardening options enabled. For full documentation on systemd's hardening options please reference: https://www.freedesktop.org/software/systemd/man/latest/systemd.exec.html -- Alexandru Mihail Sun, 14 Apr 2024 15:12:29 +0300