Parent: caeabc41274fce997edf9314de1d7f1e9ae04055
Author: Craig Andrews <candrews@integralblue.com>
Committer: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Date: 2022-01-31 20:37:54
Tree: e83c84804bea9da4e1277b7e88d67bf866d6e9cd
systemd: Add PrivateTmp and NoNewPrivileges options PrivateTmp makes bluetoothd's /tmp and /var/tmp be inside a different namespace. This is useful to secure access to temporary files of the process. NoNewPrivileges ensures that service process and all its children can never gain new privileges through execve(), lowering the risk of possible privilege escalations.
Diffstat
| M | src/bluetooth.service.in | | | 6 | ++++++ |
1 files changed, 6 insertions(+), 0 deletions(-)