Commit: 8d2db81eb7f508bbe4c89c3e9178a11ee086912e
Parent: caeabc41274fce997edf9314de1d7f1e9ae04055
Author: Craig Andrews <candrews@integralblue.com>
Committer: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Date: 2022-01-31 20:37:54
Tree: e83c84804bea9da4e1277b7e88d67bf866d6e9cd

systemd: Add PrivateTmp and NoNewPrivileges options PrivateTmp makes bluetoothd's /tmp and /var/tmp be inside a different namespace. This is useful to secure access to temporary files of the process. NoNewPrivileges ensures that service process and all its children can never gain new privileges through execve(), lowering the risk of possible privilege escalations.

Diffstat

M src/bluetooth.service.in | 6 ++++++

1 files changed, 6 insertions(+), 0 deletions(-)

View Full Diff | Patch