Add CAP_NET_ADMIN and CAP_NET_RAW to xtables-muti for nether 29/99429/2
authorjooseong lee <jooseong.lee@samsung.com>
Wed, 23 Nov 2016 01:23:15 +0000 (10:23 +0900)
committerjooseong lee <jooseong.lee@samsung.com>
Wed, 23 Nov 2016 01:28:07 +0000 (10:28 +0900)
refer to: https://review.tizen.org/gerrit/#/c/79675/

Change-Id: I993819b50d56812fe27360999093d4fccd5351e4
Signed-off-by: jooseong lee <jooseong.lee@samsung.com>
config/set_capability

index e29d7cf4106918c3d4ff24ecfcaa7b9e78c9c8c9..0d6d0fe0ad9433527188ec0af651bc8b50b801fb 100755 (executable)
@@ -336,3 +336,14 @@ fi
 if [ -e "/usr/bin/data-provider-master" ]
 then /usr/sbin/setcap cap_dac_override=eip /usr/bin/data-provider-master
 fi
+
+# Package               platform/upstream/iptables
+# Owner                 Jooseong Lee(jooseong.lee@samsung.com)
+# Date                  Nov 23, 2016
+# Required              cap_net_admin, cap_net_raw
+# cap_net_admin         to work netfilter on nether
+# cap_net_raw           to restore firewall on nether
+
+if [ -e "/usr/sbin/xtables-multi" ]
+then /usr/sbin/setcap cap_net_admin,cap_net_raw=ei /usr/sbin/xtables-multi
+fi