diff --git a/harden_udisks2-zram-setup@.service.patch b/harden_udisks2-zram-setup@.service.patch new file mode 100644 index 0000000..7eaa59f --- /dev/null +++ b/harden_udisks2-zram-setup@.service.patch @@ -0,0 +1,16 @@ +Index: udisks-2.9.4/modules/zram/data/udisks2-zram-setup@.service.in +=================================================================== +--- udisks-2.9.4.orig/modules/zram/data/udisks2-zram-setup@.service.in ++++ udisks-2.9.4/modules/zram/data/udisks2-zram-setup@.service.in +@@ -5,6 +5,11 @@ After=dev-%i.device + Requires=dev-%i.device + + [Service] ++# added automatically, for details please see ++# https://en.opensuse.org/openSUSE:Security_Features#Systemd_hardening_effort ++ProtectHostname=true ++RestrictRealtime=true ++# end of automatic additions + Type=oneshot + RemainAfterExit=no + EnvironmentFile=-@zramconfdir@/%i diff --git a/harden_udisks2.service.patch b/harden_udisks2.service.patch new file mode 100644 index 0000000..e944b07 --- /dev/null +++ b/harden_udisks2.service.patch @@ -0,0 +1,16 @@ +Index: udisks-2.9.4/data/udisks2.service.in +=================================================================== +--- udisks-2.9.4.orig/data/udisks2.service.in ++++ udisks-2.9.4/data/udisks2.service.in +@@ -3,6 +3,11 @@ Description=Disk Manager + Documentation=man:udisks(8) + + [Service] ++# added automatically, for details please see ++# https://en.opensuse.org/openSUSE:Security_Features#Systemd_hardening_effort ++ProtectHostname=true ++RestrictRealtime=true ++# end of automatic additions + Type=dbus + BusName=org.freedesktop.UDisks2 + ExecStart=@udisksdprivdir@/udisksd diff --git a/udisks2.changes b/udisks2.changes index edb0e0e..169538f 100644 --- a/udisks2.changes +++ b/udisks2.changes @@ -1,3 +1,10 @@ +------------------------------------------------------------------- +Fri May 20 07:45:36 UTC 2022 - Johannes Segitz + +- Added hardening to systemd service(s) (bsc#1181400). Added patch(es): + * harden_udisks2-zram-setup@.service.patch + * harden_udisks2.service.patch + ------------------------------------------------------------------- Mon Jan 31 15:28:11 UTC 2022 - Bjørn Lie diff --git a/udisks2.spec b/udisks2.spec index c85087e..fced589 100644 --- a/udisks2.spec +++ b/udisks2.spec @@ -30,6 +30,8 @@ License: GPL-2.0-or-later AND LGPL-2.0-or-later Group: System/Daemons URL: https://github.com/storaged-project/udisks Source0: %{url}/releases/download/udisks-%{version}/udisks-%{version}.tar.bz2 +Patch0: harden_udisks2-zram-setup@.service.patch +Patch1: harden_udisks2.service.patch BuildRequires: chrpath BuildRequires: docbook-xsl-stylesheets BuildRequires: gobject-introspection-devel >= 0.6.2