Você pode executar um processo com systemd-run
e ter ReadOnlyDirectories
definido desde v228
:
A number of properties previously only settable in unit files are now also available as properties to set when creating transient units programmatically via the bus, as it is exposed with
systemd-run
's --property=
setting. Specifically, these are:SyslogIdentifier=
,SyslogLevelPrefix=
,TimerSlackNSec=
,OOMScoreAdjust=
,EnvironmentFile=
,ReadWriteDirectories=
,ReadOnlyDirectories=
,InaccessibleDirectories=
,ProtectSystem=
,ProtectHome=
,RuntimeDirectory=
.