diff --git a/0004-systemd-More-lockdown.patch b/0004-systemd-More-lockdown.patch deleted file mode 100644 index 4f9c218..0000000 --- a/0004-systemd-More-lockdown.patch +++ /dev/null @@ -1,34 +0,0 @@ -From a6963e0402695d7b6a89c1b1c75c40dbd8fcde52 Mon Sep 17 00:00:00 2001 -From: Bastien Nocera -Date: Wed, 13 Sep 2017 15:38:26 +0200 -Subject: [PATCH 4/4] systemd: More lockdown - -bluetoothd does not need to execute mapped memory, or real-time -access, so block those. ---- - src/bluetooth.service.in | 6 ++++++ - 1 file changed, 6 insertions(+) - -diff --git a/src/bluetooth.service.in b/src/bluetooth.service.in -index 4daedef2a..f18801866 100644 ---- a/src/bluetooth.service.in -+++ b/src/bluetooth.service.in -@@ -22,9 +22,15 @@ ProtectControlGroups=true - ReadWritePaths=@statedir@ - ReadOnlyPaths=@confdir@ - -+# Execute Mappings -+MemoryDenyWriteExecute=true -+ - # Privilege escalation - NoNewPrivileges=true - -+# Real-time -+RestrictRealtime=true -+ - [Install] - WantedBy=bluetooth.target - Alias=dbus-org.bluez.service --- -2.21.0 -