From @Hermes's review (31 Aug, verified): all 11 carwatch-*.service units run with no sandboxing directives. Cheap win, and the /api/update RCE surface (#13) makes it matter more. Suggested baseline for every unit: NoNewPrivileges=yes, ProtectSystem=strict (+ReadWritePaths for its state dir), ProtectHome=read-only where possible.
From @Hermes's review (31 Aug, verified): all 11 carwatch-*.service units run with no sandboxing directives. Cheap win, and the /api/update RCE surface (#13) makes it matter more. Suggested baseline for every unit: NoNewPrivileges=yes, ProtectSystem=strict (+ReadWritePaths for its state dir), ProtectHome=read-only where possible.