diff --git a/sccache-dist-builder.service b/sccache-dist-builder.service index dc94ea1..4febc0d 100644 --- a/sccache-dist-builder.service +++ b/sccache-dist-builder.service @@ -3,6 +3,19 @@ Description=sccache-dist builder After=chronyd.service ntpd.service network-online.target [Service] +# added automatically, for details please see +# https://en.opensuse.org/openSUSE:Security_Features#Systemd_hardening_effort +ProtectSystem=full +ProtectHome=read-only +PrivateDevices=true +ProtectHostname=true +ProtectClock=true +ProtectKernelTunables=true +ProtectKernelModules=true +ProtectKernelLogs=true +ProtectControlGroups=true +RestrictRealtime=true +# end of automatic additions User=0 Type=simple CacheDirectory=sccache-builder diff --git a/sccache-dist-scheduler.service b/sccache-dist-scheduler.service index e0ce8d1..18fadf3 100644 --- a/sccache-dist-scheduler.service +++ b/sccache-dist-scheduler.service @@ -3,6 +3,19 @@ Description=sccache-dist server After=chronyd.service ntpd.service network-online.target [Service] +# added automatically, for details please see +# https://en.opensuse.org/openSUSE:Security_Features#Systemd_hardening_effort +ProtectSystem=full +ProtectHome=read-only +PrivateDevices=true +ProtectHostname=true +ProtectClock=true +ProtectKernelTunables=true +ProtectKernelModules=true +ProtectKernelLogs=true +ProtectControlGroups=true +RestrictRealtime=true +# end of automatic additions DynamicUser=yes Type=simple Environment="RUST_LOG=sccache=info" diff --git a/sccache.changes b/sccache.changes index 9314ad6..7b48cb4 100644 --- a/sccache.changes +++ b/sccache.changes @@ -1,3 +1,10 @@ +------------------------------------------------------------------- +Tue Nov 16 15:21:57 UTC 2021 - Johannes Segitz + +- Added hardening to systemd service(s) (bsc#1181400). Modified: + * sccache-dist-builder.service + * sccache-dist-scheduler.service + ------------------------------------------------------------------- Wed Nov 3 00:07:45 UTC 2021 - William Brown