So you think that systemd-timesyncd's service file shouldn't choose the uid at service-start time.
That's not really the issue though. The issue is that for service isolation reasons (related to choosing the uid at service-start time), the service file wants to run systemd-timesyncd in a private mount namespace, but it is failing to properly set up that namespace. That's a more general issue, as there are a number of things that could trigger running the service in a private mount namespace; not just DynamicUser.
As I understand the bug, the problem is in systemd's version of the `mount --make-rslave /` step, which (for a reason unknown to me) tries to stat (as root) the mountpoint first, and if the mountpoint is on a remote FS that might fail, and systemd isn't correctly handling that.
Ironically, the alternative approach here is more descriptive and less imperative package management.
Witness manifest files on the old BSD pkg system. Rather than every package maintainer writing an install/deinstall script to invoke the relevant account database tools, packages place a @newuser or @newgroup directive in the file and the packaging system handles creating and deleting the account at appropriate times.
But that's not all it does and the dependencies of systemd alongside making systemd a dependency, results in a very different observable reality.
Obviously there's so much inertia in the existing system that it could realistically never happen at this point, but one can dream, right?
[0] Kind of like e.g. /etc/services but with UUIDs.
My point wasn't so much that I had the perfect solution and that I'd thought of everything. It's that there are much better systems and that we should actually strive to get there.
Some of the more interesting ideas that people have had, in my view, have been:
* ID systems that introduce hierarchies, allowing (say) a user to create multiple sub-users (one for running the WWW browser, one for running the office suite, one for running the chat program, ...);
* proper nonce ID creation with segregation guarantees (c.f. nonce SIDs in the Windows NT world); and
* IDs that are reference counted, accessible via descriptors, passable from process to process via descriptor-passing mechanisms, and explicitly supplied in system calls for opening/creating things.