Apply deny policy for default context in dbus conf 09/177909/3 accepted/tizen/unified/20180508.134730 submit/tizen/20180508.021954
authorSeungbae Shin <seungbae.shin@samsung.com>
Fri, 4 May 2018 09:06:50 +0000 (18:06 +0900)
committerSeungbae Shin <seungbae.shin@samsung.com>
Fri, 4 May 2018 11:09:22 +0000 (20:09 +0900)
Applied to both sound-server / focus-server

[Version] 0.12.16
[Issue Type] Security

Change-Id: Idb3c93ae5397269089eed1f0f351d5ff467b0878

packaging/focus-server.conf
packaging/libmm-sound.spec
packaging/sound-server.conf

index 74f303f..f471194 100644 (file)
@@ -3,19 +3,17 @@
  "http://www.freedesktop.org/standards/dbus/1.0/busconfig.dtd">
 
 <busconfig>
-  <policy user="system">
+  <policy user="multimedia_fw">
     <allow own="org.tizen.FocusServer"/>
     <allow send_destination="org.tizen.FocusServer"/>
-    <allow receive_sender="org.tizen.FocusServer"/>
   </policy>
   <policy user="root">
-    <allow own_prefix="org.tizen.FocusServer"/>
+    <allow own="org.tizen.FocusServer"/>
     <allow send_destination="org.tizen.FocusServer"/>
-    <allow receive_sender="org.tizen.FocusServer"/>
   </policy>
   <policy context="default">
-    <allow own_prefix="org.tizen.FocusServer"/>
-    <allow send_destination="org.tizen.FocusServer"/>
-    <allow receive_sender="org.tizen.FocusServer"/>
+    <deny own="org.tizen.FocusServer"/>
+    <deny send_destination="org.tizen.FocusServer"/>
+    <allow send_destination="org.tizen.FocusServer" send_interface="org.tizen.FocusServer1"/>
   </policy>
 </busconfig>
index e583ac5..3b5668f 100644 (file)
@@ -1,6 +1,6 @@
 Name:       libmm-sound
 Summary:    MMSound Package contains client lib and sound_server binary
-Version:    0.12.15
+Version:    0.12.16
 Release:    0
 Group:      System/Libraries
 License:    Apache-2.0
index 9329be6..9fd39a8 100644 (file)
@@ -3,19 +3,18 @@
  "http://www.freedesktop.org/standards/dbus/1.0/busconfig.dtd">
 
 <busconfig>
-  <policy user="system">
+  <policy user="multimedia_fw">
     <allow own="org.tizen.SoundServer"/>
     <allow send_destination="org.tizen.SoundServer"/>
-    <allow receive_sender="org.tizen.SoundServer"/>
   </policy>
   <policy user="root">
-    <allow own_prefix="org.tizen.SoundServer"/>
+    <allow own="org.tizen.SoundServer"/>
     <allow send_destination="org.tizen.SoundServer"/>
-    <allow receive_sender="org.tizen.SoundServer"/>
   </policy>
   <policy context="default">
-    <allow own_prefix="org.tizen.SoundServer"/>
-    <allow send_destination="org.tizen.SoundServer"/>
-    <allow receive_sender="org.tizen.SoundServer"/>
+    <deny own="org.tizen.SoundServer"/>
+    <deny send_destination="org.tizen.SoundServer"/>
+    <allow send_destination="org.tizen.SoundServer" send_interface="org.tizen.SoundServer1"/>
   </policy>
 </busconfig>
+