Modify User/Group for media-controller to enhance security 12/70612/2 accepted/tizen/common/20160526.145820 accepted/tizen/ivi/20160602.020544 accepted/tizen/mobile/20160602.020416 accepted/tizen/tv/20160602.020518 accepted/tizen/wearable/20160602.020451 submit/tizen/20160524.060031
authorJiyong Min <jiyong.min@samsung.com>
Fri, 20 May 2016 01:00:58 +0000 (10:00 +0900)
committerJiyong Min <jiyong.min@samsung.com>
Fri, 20 May 2016 01:42:47 +0000 (10:42 +0900)
Change-Id: I15d9a5da4a9117eb6a80f4ad178d89507d3d0c65
Signed-off-by: Jiyong Min <jiyong.min@samsung.com>
packaging/capi-media-controller.spec
packaging/mediacontroller.service
packaging/mediacontroller.socket

index 20cb364..3fad5a1 100644 (file)
@@ -1,6 +1,6 @@
 Name:       capi-media-controller
 Summary:    A media controller library in Tizen Native API
-Version:    0.1.19
+Version:    0.1.20
 Release:    1
 Group:      Multimedia/API
 License:    Apache-2.0
@@ -100,9 +100,7 @@ install -m 0775 %{SOURCE1001} %{buildroot}%{_bindir}/media-controller_create_db.
 %endif
 
 %post
-%if 0%{?multi_user}
-chgrp %TZ_SYS_USER_GROUP %{_bindir}/media-controller_create_db.sh
-%endif
+
 %postun
 
 %files
@@ -118,7 +116,7 @@ chgrp %TZ_SYS_USER_GROUP %{_bindir}/media-controller_create_db.sh
 %{_bindir}/media-controller_create_db.sh
 %endif
 %manifest media-controller-service.manifest
-%defattr(-,system,system,-)
+%defattr(-,multimedia_fw,multimedia_fw,-)
 %{_unitdir}/mediacontroller.service
 %{_unitdir}/mediacontroller.socket
 %{_unitdir}/sockets.target.wants/mediacontroller.socket
index f8fd79d..fc2b419 100755 (executable)
@@ -2,6 +2,8 @@
 Description=Media controller
 
 [Service]
+Owner=multimedia_fw
+Group=multimedia_fw
 ExecStart=/usr/bin/mediacontroller
 Type=simple
 
index 04ff4ec..af9d83a 100644 (file)
@@ -2,6 +2,8 @@
 Description=MediaController Service socket
 
 [Socket]
+SocketOwner=multimedia_fw
+SocketGroup=multimedia_fw
 ListenStream=/run/.mediacontroller.sock
 Service=mediacontroller.service