Blame SOURCES/0004-systemd-More-lockdown.patch

ee2351
From a6963e0402695d7b6a89c1b1c75c40dbd8fcde52 Mon Sep 17 00:00:00 2001
ee2351
From: Bastien Nocera <hadess@hadess.net>
ee2351
Date: Wed, 13 Sep 2017 15:38:26 +0200
ee2351
Subject: [PATCH 4/4] systemd: More lockdown
ee2351
ee2351
bluetoothd does not need to execute mapped memory, or real-time
ee2351
access, so block those.
ee2351
---
ee2351
 src/bluetooth.service.in | 6 ++++++
ee2351
 1 file changed, 6 insertions(+)
ee2351
ee2351
diff --git a/src/bluetooth.service.in b/src/bluetooth.service.in
ee2351
index 4daedef2a..f18801866 100644
ee2351
--- a/src/bluetooth.service.in
ee2351
+++ b/src/bluetooth.service.in
ee2351
@@ -22,9 +22,15 @@ ProtectControlGroups=true
ee2351
 ReadWritePaths=@statedir@
ee2351
 ReadOnlyPaths=@confdir@
ee2351
 
ee2351
+# Execute Mappings
ee2351
+MemoryDenyWriteExecute=true
ee2351
+
ee2351
 # Privilege escalation
ee2351
 NoNewPrivileges=true
ee2351
 
ee2351
+# Real-time
ee2351
+RestrictRealtime=true
ee2351
+
ee2351
 [Install]
ee2351
 WantedBy=bluetooth.target
ee2351
 Alias=dbus-org.bluez.service
ee2351
-- 
ee2351
2.21.0
ee2351