service: harden the NetworkManager service a bit
authorLubomir Rintel <lkundrak@v3.sk>
Thu, 4 Jun 2015 12:30:02 +0000 (14:30 +0200)
committerLubomir Rintel <lkundrak@v3.sk>
Wed, 1 Jul 2015 14:26:15 +0000 (16:26 +0200)
Tested with dnsmasq (ipv4.method=shared), openvpn & vpnc.

https://bugzilla.gnome.org/show_bug.cgi?id=750598

data/NetworkManager.service.in

index 980573d..42b43e3 100644 (file)
@@ -11,6 +11,9 @@ ExecStart=@sbindir@/NetworkManager --no-daemon
 Restart=on-failure
 # NM doesn't want systemd to kill its children for it
 KillMode=process
+CapabilityBoundingSet=CAP_NET_ADMIN CAP_DAC_OVERRIDE CAP_NET_RAW CAP_NET_BIND_SERVICE CAP_SETGID CAP_SETUID CAP_SYS_MODULE
+ProtectSystem=true
+ProtectHome=read-only
 
 [Install]
 WantedBy=multi-user.target