Skip to content

A drop-in that adds a StateDirectory= reorders $STATE_DIRECTORY, and the daemon writes to whichever sorts first

scope: generic · severity: trap · confidence: proven · subsystem: build

Do not add a second StateDirectory= in a drop-in to give a sandboxed service somewhere else to write. systemd sorts the unit’s directories before exporting them, so $STATE_DIRECTORY does not follow the order they were written in. Any daemon that reads the first entry of that list (fprintd does, for its per-user prints) may start writing its own state into the directory you added for something else. fprintd then reads every entry there as a username.

Give the extra directory write access instead: ReadWritePaths=-/var/lib/<dir> in the drop-in, with the directory created by a tmpfiles.d d line. It needs to exist before the service starts, because ProtectSystem=strict leaves /var/lib read-only inside.