Good point. I’ll have to stop using immutable and stay with atomic (and declarative).
Interestingly /bin
and /usr/bin
are not in PATH by default, so /bin/chewy
can only be executed by its path directly and won’t affect the systems reliability.
You’d need a second Signal instance. There’s only global privacy options.