Hi, the section about NoNewPrivileges in systemd.exec(5) reads "it also prohibits UID changes of any kind". This lead me to believe that the daemon started by a unit file that enables NoNewPrivilege could not change its UID (e.g. to drop root privileges), which is apparently not the case, as Ansgar Burchardt kindly explained to me on https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=756604#10. Thanks a lot for writing and maintaining systemd, Cheers!
Fixed in d974f949f10d6945e1abe9bc6525e676bc515928
Use of freedesktop.org services, including Bugzilla, is subject to our Code of Conduct. How we collect and use information is described in our Privacy Policy.