Blame SOURCES/0004-systemd-More-lockdown.patch

e0630b
From 171d812218883281fed57b57fafd5c18eac441ac Mon Sep 17 00:00:00 2001
e0630b
From: Bastien Nocera <hadess@hadess.net>
e0630b
Date: Wed, 13 Sep 2017 15:38:26 +0200
e0630b
Subject: [PATCH 4/4] systemd: More lockdown
e0630b
e0630b
bluetoothd does not need to execute mapped memory, or real-time
e0630b
access, so block those.
e0630b
---
e0630b
 src/bluetooth.service.in | 6 ++++++
e0630b
 1 file changed, 6 insertions(+)
e0630b
e0630b
diff --git a/src/bluetooth.service.in b/src/bluetooth.service.in
e0630b
index 7e55b5043..e8267b338 100644
e0630b
--- a/src/bluetooth.service.in
e0630b
+++ b/src/bluetooth.service.in
e0630b
@@ -22,9 +22,15 @@ ProtectControlGroups=true
e0630b
 ReadWritePaths=@statedir@
e0630b
 ReadOnlyPaths=@confdir@
e0630b
 
e0630b
+# Execute Mappings
e0630b
+MemoryDenyWriteExecute=true
e0630b
+
e0630b
 # Privilege escalation
e0630b
 NoNewPrivileges=true
e0630b
 
e0630b
+# Real-time
e0630b
+RestrictRealtime=true
e0630b
+
e0630b
 [Install]
e0630b
 WantedBy=bluetooth.target
e0630b
 Alias=dbus-org.bluez.service
e0630b
-- 
e0630b
2.14.1
e0630b