Systemd says user nobody is not safe; other refs say different

In reviewing system message emails in mutt, systemd says user nobody is not safe. See below;

--------------------- Systemd Begin ------------------------

 Configuration errors:
    PIDFile= references a path below legacy directory /var/run/: 2 Time(s)
    **Special user nobody configured, this is not safe!:** 1 Time(s)
    Standard output type syslog is obsolete, automatically updating to journal: 12 Time(s)

Other refs differ. See below:

(https://www.baeldung.com/linux/nobody-user)

Any ideas if systemd is right or not and if so, how to get rid of nobody user.
thanks, tom kosvic

It’s part of the install system-user-nobody what process is running using nobody?

Tried a search for “nobody” user files. Note: /run/media/tom/WD_linux/ is an external harddisk used for timeshift backups.
I think mlocate has been supplanted by plocate for the “locate” app.

tom@mydesktop: ~ $ sudo find / -user nobody -type f
find: ‘/proc/3448/task/3448/net’: Invalid argument
find: ‘/proc/3448/net’: Invalid argument
find: ‘/proc/6247/task/6247/net’: Invalid argument
find: ‘/proc/6247/net’: Invalid argument
find: ‘/proc/1683727’: No such file or directory
find: ‘/proc/1683729/task/1683729/fd/6’: No such file or directory
find: ‘/proc/1683729/task/1683729/fdinfo/6’: No such file or directory
find: ‘/proc/1683729/fd/5’: No such file or directory
find: ‘/proc/1683729/fdinfo/5’: No such file or directory
/run/media/tom/WD_book_linux/timeshift/snapshots/2026-06-10_13-00-00/localhost/var/lib/mlocate/mlocate.db.mSOCtL
/run/media/tom/WD_book_linux/timeshift/snapshots/2026-06-10_13-00-00/localhost/var/lib/mlocate/mlocate.db.Pg5nEJ
/run/media/tom/WD_book_linux/timeshift/snapshots/2026-06-10_13-00-00/localhost/var/lib/mlocate/mlocate.db.6RtvVU
/run/media/tom/WD_book_linux/timeshift/snapshots/2026-06-10_13-00-00/localhost/var/lib/mlocate/mlocate.db.sWsMeA
/run/media/tom/WD_book_linux/timeshift/snapshots/2026-03-30_05-00-08/localhost/var/lib/mlocate/mlocate.db
/run/media/tom/WD_book_linux/timeshift/snapshots/2026-03-30_05-00-08/localhost/var/lib/mlocate/mlocate.db.mSOCtL
/run/media/tom/WD_book_linux/timeshift/snapshots/2026-03-30_05-00-08/localhost/var/lib/mlocate/mlocate.db.Pg5nEJ
/run/media/tom/WD_book_linux/timeshift/snapshots/2026-03-30_05-00-08/localhost/var/lib/mlocate/mlocate.db.6RtvVU
/run/media/tom/WD_book_linux/timeshift/snapshots/2026-03-30_05-00-08/localhost/var/lib/mlocate/mlocate.db.sWsMeA
/run/media/tom/WD_book_linux/timeshift/snapshots/2026-05-19_07-52-47/localhost/var/lib/mlocate/mlocate.db.mSOCtL
/run/media/tom/WD_book_linux/timeshift/snapshots/2026-05-19_07-52-47/localhost/var/lib/mlocate/mlocate.db.Pg5nEJ
/run/media/tom/WD_book_linux/timeshift/snapshots/2026-05-19_07-52-47/localhost/var/lib/mlocate/mlocate.db.6RtvVU
/run/media/tom/WD_book_linux/timeshift/snapshots/2026-05-19_07-52-47/localhost/var/lib/mlocate/mlocate.db.sWsMeA
/run/media/tom/WD_book_linux/timeshift/snapshots/2026-05-13_10-00-00/localhost/var/lib/mlocate/mlocate.db.mSOCtL
/run/media/tom/WD_book_linux/timeshift/snapshots/2026-05-13_10-00-00/localhost/var/lib/mlocate/mlocate.db.Pg5nEJ
/run/media/tom/WD_book_linux/timeshift/snapshots/2026-05-13_10-00-00/localhost/var/lib/mlocate/mlocate.db.6RtvVU
/run/media/tom/WD_book_linux/timeshift/snapshots/2026-05-13_10-00-00/localhost/var/lib/mlocate/mlocate.db.sWsMeA
/run/media/tom/WD_book_linux/timeshift/snapshots/2026-05-23_07-00-00/localhost/var/lib/mlocate/mlocate.db.mSOCtL
/run/media/tom/WD_book_linux/timeshift/snapshots/2026-05-23_07-00-00/localhost/var/lib/mlocate/mlocate.db.Pg5nEJ
/run/media/tom/WD_book_linux/timeshift/snapshots/2026-05-23_07-00-00/localhost/var/lib/mlocate/mlocate.db.6RtvVU
/run/media/tom/WD_book_linux/timeshift/snapshots/2026-05-23_07-00-00/localhost/var/lib/mlocate/mlocate.db.sWsMeA
/run/media/tom/WD_book_linux/timeshift/snapshots/2026-06-13_11-00-03/localhost/var/lib/mlocate/mlocate.db.mSOCtL
/run/media/tom/WD_book_linux/timeshift/snapshots/2026-06-13_11-00-03/localhost/var/lib/mlocate/mlocate.db.Pg5nEJ
/run/media/tom/WD_book_linux/timeshift/snapshots/2026-06-13_11-00-03/localhost/var/lib/mlocate/mlocate.db.6RtvVU
/run/media/tom/WD_book_linux/timeshift/snapshots/2026-06-13_11-00-03/localhost/var/lib/mlocate/mlocate.db.sWsMeA
/run/media/tom/WD_book_linux/backintime/mydesktop/root/2/20260622-010003-132/backup/home/System Volume Information/IndexerVolumeGuid
/run/media/tom/WD_book_linux/backintime/mydesktop/root/2/20260525-010001-513/backup/home/System Volume Information/IndexerVolumeGuid
/run/media/tom/WD_book_linux/backintime/mydesktop/root/2/20260525-010001-513/backup/var/lib/mlocate/mlocate.db.mSOCtL
/run/media/tom/WD_book_linux/backintime/mydesktop/root/2/20260525-010001-513/backup/var/lib/mlocate/mlocate.db.Pg5nEJ
/run/media/tom/WD_book_linux/backintime/mydesktop/root/2/20260525-010001-513/backup/var/lib/mlocate/mlocate.db.6RtvVU
/run/media/tom/WD_book_linux/backintime/mydesktop/root/2/20260525-010001-513/backup/var/lib/mlocate/mlocate.db.sWsMeA
/run/media/tom/WD_book_linux/backintime/mydesktop/root/2/20260615-010001-792/backup/home/System Volume Information/IndexerVolumeGuid
find: ‘/run/user/1000/gvfs’: Permission denied
/home/System Volume Information/IndexerVolumeGuid
find: ‘/tmp/.mount_JoplinciW81R’: Permission denied
tom@mydesktop: ~ $ 

Look at the systemd services…

fgrep -r "User=nobody" /usr/lib/systemd/system/* /etc/systemd/system/*
tom@mydesktop: ~ $ fgrep -r "User=nobody" /usr/lib/systemd/system/* /etc/systemd/system/*
/etc/systemd/system/rlmsrvssq.service:User=nobody
tom@mydesktop: ~ $ 

What service is that? I normally create my own user for out of scope services.

Edit the service and comment out User=nobodyand adding DynamicUser=yes, systemctl daemon-reload and see if the service runs.

The warning is correct for two reasons

  • If more than one service is configured as ‘nobody’ those services have access to each others files. You should create individual users for each service.
  • User ‘nobody’ has special meaning to NFS. Using root_squash remaps root owned files to nobody. In NFS4, any unknown user is mapped to nobody. In either case, now with a service running as nobody, you probably have a bunch of access you didn’t intend.

Running services as nobody is an old and no longer recommended setup. The LSB has user nobody as used for only NFS.

I found this:

tom@mydesktop: /var/lib/plocate $ l
total 75664
drwxr-xr-x.  2 root root       4096 Jun 22 13:00 ./
drwxr-xr-x. 95 root root       4096 Jun 18 19:52 ../
-rw-r--r--.  1 root root        183 Jan 25 11:12 CACHEDIR.TAG
-rw-r-----.  1 root nobody 77461343 Jun 22 13:00 plocate.db

I have no idea what service rlmsrvssq is. File contents of rlmsrvssq.service are below:

[Unit]
Description=SSQ RLM Service
After=network.target

[Service]
User=nobody
Group=nobody

ExecStart=/home/tom/SolidSQUAD_License_Servers/Bin/rlm -c /home/tom/SolidSQUAD_License_Servers/Licenses/rlm_SSQ.lic -dlog /home/tom/SolidSQUAD_License_Servers/Logs/rlm.log -nows -noudp

StartLimitInterval=120s
StartLimitBurst=5
Type=simple
TimeoutStopSec=60s
TimeoutStartSec=60s

[Install]
WantedBy=multi-user.target


This system was upgraded from leap 15.6 to tumbleweed using migration tool. I don’t remember ever seeing a"nobody" while it was on leap.

So you user was connecting to a license server, is it used anymore, if not delete the service.

The plocate.db file is using the nobody group, not user…

After some research, rlm* looks like it might be from reprise software that licenses “tecplot” a well known engineering plotting data display program . I might have tried that a decade or so ago and this might be the remnants.

Do I just delete the file “/etc/systemd/system/rlmsrvssq.service” to delete the service?

thanks, tom kosvic

Check the status first, systemctl status rlmsrvssq.service is not running, yes just delete. Does the directory /home/tom/SolidSQUAD_License_Servers exist?

Service is not active. No directory for /home/tom/SolidSQUAD_License_Server.
Service file was deleted. It was not even executible (+x).

tom@mydesktop: ~ $ systemctl status rlmsrvssq.service
× rlmsrvssq.service - SSQ RLM Service
     Loaded: loaded (/etc/systemd/system/rlmsrvssq.service; enabled; preset: disabled)
     Active: failed (Result: exit-code) since Mon 2026-06-22 18:22:54 CDT; 2h 58min ago
   Duration: 762ms
 Invocation: 0861beb0dfd843a6b7c65f37861b0427
    Process: 1167 ExecStart=/home/tom/SolidSQUAD_License_Servers/Bin/rlm -c /home/tom/SolidSQUAD_License_Servers/Licenses/rlm_SSQ.lic -dlog /home/tom/SolidSQUAD_License_Servers/Logs/rlm.>
   Main PID: 1167 (code=exited, status=203/EXEC)
        CPU: 6ms

Jun 22 18:22:53 mydesktop systemd[1]: Started SSQ RLM Service.
Jun 22 18:22:54 mydesktop (rlm)[1167]: rlmsrvssq.service: Unable to locate executable '/home/tom/SolidSQUAD_License_Servers/Bin/rlm': No such file or directory
Jun 22 18:22:54 mydesktop (rlm)[1167]: rlmsrvssq.service: Failed at step EXEC spawning /home/tom/SolidSQUAD_License_Servers/Bin/rlm: No such file or directory
Jun 22 18:22:54 mydesktop systemd[1]: rlmsrvssq.service: Main process exited, code=exited, status=203/EXEC
Jun 22 18:22:54 mydesktop systemd[1]: rlmsrvssq.service: Failed with result 'exit-code'.
tom@mydesktop: ~ $ 

@tckosvic systemd services are not required to be executable, they need to be 0644…

0644 executes by systemd, well that’s an interesting fact

A service is really just a config file for systemd to process so it’s only reading it.