Hi again, On 23 Jan 2026 at 07:09:07, Carles Pina i Estany wrote:
> > The systemd unit recently introduced at least shrinks down the > > permissions to the dynamic user permissions, so it actually reduces > > the concern to "somebody that has localhost tcp access has access as > > anonymous user", which is way better than "somebody that has localhost > > tcp access has access as whatever user who happened to start festival." > > Well, this is thanks to the "festival --server" rejecting connections > from outside localhost. > > If I enable the socket activation and *after* "festival --server" runs: > festival is reachable from outside localhost. But it drops the > connections. I see the clients reaching it via: > > carles@pinux:~$ sudo journalctl -u festival -f > > I'll check how to make festival binding only to localhost (I think that > some options could be passed to "festival --server" but I don't know if > this is possible...) I think that this was a PEBKAC (bad testing). When using the festival.socket, I cannot reach festival from outside localhost. -- Carles Pina i Estany https://carles.pina.cat | [email protected] | [email protected]
signature.asc
Description: PGP signature

