Blame SOURCES/0004-systemd-More-lockdown.patch

1835d6
From 9a7872f04cb748e8de743d9136ecd91539d13cb7 Mon Sep 17 00:00:00 2001
1835d6
From: Gopal Tiwari <gtiwari@redhat.com>
1835d6
Date: Mon, 8 Jun 2020 19:56:42 +0530
1835d6
Subject: [PATCH BlueZ 4/4] systemd: More lockdown
1835d6
d15ffa
From 171d812218883281fed57b57fafd5c18eac441ac Mon Sep 17 00:00:00 2001
d15ffa
From: Bastien Nocera <hadess@hadess.net>
d15ffa
Date: Wed, 13 Sep 2017 15:38:26 +0200
1835d6
1835d6
systemd: More lockdown
d15ffa
d15ffa
bluetoothd does not need to execute mapped memory, or real-time
d15ffa
access, so block those.
d15ffa
---
d15ffa
 src/bluetooth.service.in | 6 ++++++
d15ffa
 1 file changed, 6 insertions(+)
d15ffa
d15ffa
diff --git a/src/bluetooth.service.in b/src/bluetooth.service.in
1835d6
index 4daedef2a..f18801866 100644
d15ffa
--- a/src/bluetooth.service.in
d15ffa
+++ b/src/bluetooth.service.in
d15ffa
@@ -22,9 +22,15 @@ ProtectControlGroups=true
d15ffa
 ReadWritePaths=@statedir@
d15ffa
 ReadOnlyPaths=@confdir@
d15ffa
 
d15ffa
+# Execute Mappings
d15ffa
+MemoryDenyWriteExecute=true
d15ffa
+
d15ffa
 # Privilege escalation
d15ffa
 NoNewPrivileges=true
d15ffa
 
d15ffa
+# Real-time
d15ffa
+RestrictRealtime=true
d15ffa
+
d15ffa
 [Install]
d15ffa
 WantedBy=bluetooth.target
d15ffa
 Alias=dbus-org.bluez.service
d15ffa
-- 
1835d6
2.21.1
d15ffa