bitcoin/harden_bitcoind.service.patch
2021-08-27 15:22:13 +00:00

22 lines
823 B
Diff

Index: bitcoin-0.21.1/contrib/init/bitcoind.service
===================================================================
--- bitcoin-0.21.1.orig/contrib/init/bitcoind.service
+++ bitcoin-0.21.1/contrib/init/bitcoind.service
@@ -69,6 +69,16 @@ NoNewPrivileges=true
# Use a new /dev namespace only populated with API pseudo devices
# such as /dev/null, /dev/zero and /dev/random.
PrivateDevices=true
+# added automatically, for details please see
+# https://en.opensuse.org/openSUSE:Security_Features#Systemd_hardening_effort
+ProtectHostname=true
+ProtectClock=true
+ProtectKernelTunables=true
+ProtectKernelModules=true
+ProtectKernelLogs=true
+ProtectControlGroups=true
+RestrictRealtime=true
+# end of automatic additions
# Deny the creation of writable and executable memory mappings.
MemoryDenyWriteExecute=true