Index: iputils-20210722/systemd/rdisc.service.in =================================================================== --- iputils-20210722.orig/systemd/rdisc.service.in +++ iputils-20210722/systemd/rdisc.service.in @@ -20,6 +20,12 @@ ProtectKernelModules=yes MemoryDenyWriteExecute=yes RestrictRealtime=yes RestrictNamespaces=yes +# added automatically, for details please see +# https://en.opensuse.org/openSUSE:Security_Features#Systemd_hardening_effort +ProtectHostname=true +ProtectClock=true +ProtectKernelLogs=true +# end of automatic additions SystemCallArchitectures=native LockPersonality=yes NoNewPrivileges=yes