Reduce privileges of generate cache service 15/325615/1 accepted/tizen_unified accepted/tizen_unified_x tizen accepted/tizen/unified/20250613.040703 accepted/tizen/unified/x/20250613.044726
authorKarol Lewandowski <k.lewandowsk@samsung.com>
Thu, 12 Jun 2025 09:54:35 +0000 (11:54 +0200)
committerKarol Lewandowski <k.lewandowsk@samsung.com>
Thu, 12 Jun 2025 10:55:09 +0000 (12:55 +0200)
root should not be needed accoring to dbus policy.

Change-Id: I2e0633b3108df5dcf5a711c76319e7ea2a919a78

packaging/sessiond.spec
src/service/sessiond-generate-cache.service

index 81788c0fc545192623dfdfa9b6c749e382a3876d..6161dc19b4c23647cdca8c0436785a52d0a8481e 100644 (file)
@@ -2,7 +2,7 @@
 
 Name:       sessiond
 Summary:    Service to manage subsessions
-Version:    10.3.1
+Version:    10.3.2
 Release:    1
 Group:      System/Management
 License:    MIT
index 66dacbc60ded282f76a748d63944212ad71df4ff..324e4f01436fc1ad2e30263dd5c52680a3a8acf8 100644 (file)
@@ -3,8 +3,8 @@ Description=Regenerate sessiond cache
 
 [Service]
 Type=oneshot
-User=root
-Group=root
+User=system_fw
+Group=system_fw
 SmackProcessLabel=System
 ExecStart=/usr/bin/busctl call --expect-reply=no -- org.tizen.sessiond /org/tizen/sessiond org.tizen.sessiond.subsession.Manager GenerateCache "i" "1"