Some checks failed
Check Flake / check-flake (push) Failing after 18s
ProtectSystem=strict with ReadWritePaths fails silently on ZFS submounts (/var/lib is a separate dataset), leaving the data dir read-only. Downgrade to ProtectSystem=full which leaves /var writable while still protecting /usr and /boot.