Created attachment 357547 [details] Patch to drop capabilities Description of problem: As part of the lowering capabilities project, we should drop all unnecessary capabilities in bluetoothd.
Created attachment 357568 [details] Patch to drop capabilities Forgot to clear the bounding set in previous patch.
Could you please send this upstream to the bluez mailing-list? The address is linux-bluetooth.org
Created attachment 359286 [details] Patch to drop capabilities This patch reworks the configure part in order to be easier to upstream.
Also, this patch needs to have Buildrequires: libcap-ng-devel added to the spec file.
Can you please make sure this gets sent upstream? Note that the configure checks would be easier if libcap-ng installed a pkg-config file...
Yes, I will send the patch upstream soon. I just finished a code review and have a few suggestions for upstream. I wanted to present the code review findings at about the same time as this patch while people are thinking about security fixes.
Patch against 4.54 was sent upstream + some bug fixes.
Fixed in rawhide for F-13: http://koji.fedoraproject.org/koji/taskinfo?taskID=1727727