From 5326b03f30b6b1d50437766afc09598a8be89f8f Mon Sep 17 00:00:00 2001 From: Lennart Poettering Date: Mon, 23 Dec 2013 20:37:00 +0100 Subject: [PATCH] units: limit caps for bus proxyd and driverd services --- units/systemd-bus-driverd.service.in | 1 + units/systemd-bus-proxyd@.service.in | 1 + 2 files changed, 2 insertions(+) diff --git a/units/systemd-bus-driverd.service.in b/units/systemd-bus-driverd.service.in index 575bddc69..0bda4037c 100644 --- a/units/systemd-bus-driverd.service.in +++ b/units/systemd-bus-driverd.service.in @@ -12,3 +12,4 @@ Description=Bus Driver Service ExecStart=@rootlibexecdir@/systemd-bus-driverd BusName=org.freedesktop.DBus WatchdogSec=1min +CapabilityBoundingSet=CAP_IPC_OWNER diff --git a/units/systemd-bus-proxyd@.service.in b/units/systemd-bus-proxyd@.service.in index 0711b48bb..1bdb459f7 100644 --- a/units/systemd-bus-proxyd@.service.in +++ b/units/systemd-bus-proxyd@.service.in @@ -14,3 +14,4 @@ Description=Legacy D-Bus Protocol Compatibility Daemon # space available for this. ExecStart=@rootlibexecdir@/systemd-bus-proxyd xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx NotifyAccess=main +CapabilityBoundingSet=CAP_IPC_OWNER -- 2.30.2