Add some groups for user session daemons
authorKidong Kim <kd0228.kim@samsung.com>
Fri, 13 May 2016 11:52:48 +0000 (20:52 +0900)
committerŁukasz Stelmach <l.stelmach@samsung.com>
Fri, 24 Feb 2017 15:08:16 +0000 (16:08 +0100)
Because user session daemons have same uid/gid with applications,
include them in specific gids for checking privilege.
The security-manager will drop these groups from applications.

Change-Id: I1ed91e75cb605a4c6bffa604fe992ec995ff2845

units/user@.service.m4.in

index 2ad2261..9957ee1 100644 (file)
@@ -21,4 +21,5 @@ Delegate=yes
 TasksMax=infinity
 Environment=DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/%U/dbus/user_bus_socket
 Capabilities=cap_mac_admin,cap_mac_override,cap_setgid=i
+SupplementaryGroups=priv_mediastorage priv_externalstorage priv_message_read priv_mapservice priv_network_get priv_internet
 SecureBits=keep-caps