Skip to main content

runtime_dropin_content

Function runtime_dropin_content 

Source
fn runtime_dropin_content() -> String
Expand description

The exact bytes the scheduler owns for its runtime (per-boot) network-sandbox unblock. Mirrors the installer’s /etc drop-in shape. An [Service] section whose empty assignments reset the loader’s RestrictAddressFamilies=/SocketBindDeny= for the next start carries the scheduler’s own marker, so the restore path can prove a file is ours byte-for-byte before removing it.