Remove unused and upstreamed patch
This commit is contained in:
parent
1b8fd108c7
commit
a6cde194db
@ -1,34 +0,0 @@
|
|||||||
From a6963e0402695d7b6a89c1b1c75c40dbd8fcde52 Mon Sep 17 00:00:00 2001
|
|
||||||
From: Bastien Nocera <hadess@hadess.net>
|
|
||||||
Date: Wed, 13 Sep 2017 15:38:26 +0200
|
|
||||||
Subject: [PATCH 4/4] systemd: More lockdown
|
|
||||||
|
|
||||||
bluetoothd does not need to execute mapped memory, or real-time
|
|
||||||
access, so block those.
|
|
||||||
---
|
|
||||||
src/bluetooth.service.in | 6 ++++++
|
|
||||||
1 file changed, 6 insertions(+)
|
|
||||||
|
|
||||||
diff --git a/src/bluetooth.service.in b/src/bluetooth.service.in
|
|
||||||
index 4daedef2a..f18801866 100644
|
|
||||||
--- a/src/bluetooth.service.in
|
|
||||||
+++ b/src/bluetooth.service.in
|
|
||||||
@@ -22,9 +22,15 @@ ProtectControlGroups=true
|
|
||||||
ReadWritePaths=@statedir@
|
|
||||||
ReadOnlyPaths=@confdir@
|
|
||||||
|
|
||||||
+# Execute Mappings
|
|
||||||
+MemoryDenyWriteExecute=true
|
|
||||||
+
|
|
||||||
# Privilege escalation
|
|
||||||
NoNewPrivileges=true
|
|
||||||
|
|
||||||
+# Real-time
|
|
||||||
+RestrictRealtime=true
|
|
||||||
+
|
|
||||||
[Install]
|
|
||||||
WantedBy=bluetooth.target
|
|
||||||
Alias=dbus-org.bluez.service
|
|
||||||
--
|
|
||||||
2.21.0
|
|
||||||
|
|
Loading…
Reference in New Issue
Block a user