http://forums.w5j6stm77zs6652pgsij4awcjeel3eco7kvipheu6mtr623eyyehj4yd.onion/t/sdwdate-failed-to-start-in-debian-12-bookworm-next-release/134?_escaped_fragment_=
I was contemplating to remove the sdwdate.postinst dynamic creation and move all to the static systemd unit file. No objection from me. At a high level, the different architectures’ syscall whitelists should provide equivalent functionality (otherwise the same application wouldn’t work on all of them), so the attack surface incurred by synchronizing them shouldn’t be very high.