add cap_net_bind_service capability 32/194432/1 accepted/tizen/unified/20181205.063340 submit/tizen/20181204.101028
authorsaerome kim <saerome.kim@samsung.com>
Tue, 4 Dec 2018 09:54:53 +0000 (18:54 +0900)
committersaerome kim <saerome.kim@samsung.com>
Tue, 4 Dec 2018 10:04:51 +0000 (19:04 +0900)
commitbbee078c6d3f8d93e99fd5b725cd02c7bd6b0c77
tree415cbd4319b3332b679d53d6773d42092687c7ac
parent34716d115e9e96465f8587742e2ad761f2618734
add cap_net_bind_service capability

- 'Permitted' capability can make a process can call
system-call without the process's inherited capabilties.
So, security team would like to remove 'Permitted' capabilty.

This change is to remove 'Permitted' capability from hostapd.
To make this, Caller (i.e., wmeshd) should have tue same capabilities as
hostapd. Therefore we set wmeshd's capabilties to match hostapd.

Change-Id: Ifa13538064b9adcb26761f4b164496f8d0027db6
Signed-off-by: saerome kim <saerome.kim@samsung.com>
packaging/wifi-mesh-manager.spec
packaging/wmeshd.service