From: keeho.yang Date: Mon, 20 Aug 2018 09:02:07 +0000 (+0900) Subject: Add cap_sys_admin capability to session-bind service X-Git-Tag: submit/tizen/20180823.013016^0 X-Git-Url: http://review.tizen.org/git/?a=commitdiff_plain;h=3344a15c4862d77d529d707df4c75ff94b4a9e2c;p=platform%2Fcore%2Fsecurity%2Fsecurity-config.git Add cap_sys_admin capability to session-bind service Change-Id: I78145edfcbbd4140a684cf8b57863f86b61357c3 --- diff --git a/config/set_capability b/config/set_capability index 195b20c..cf3dd32 100755 --- a/config/set_capability +++ b/config/set_capability @@ -618,6 +618,16 @@ if [ -e "/usr/bin/audit-trail-daemon" ] then /usr/sbin/setcap cap_audit_control,cap_audit_write=ei /usr/bin/audit-trail-daemon fi +# Package platform/adaptation/system-plugin +# Owner Insun Pyo(insun.pyo@samsung.com) +# Date Aug 20, 2018 +# Required cap_sys_admin +# cap_sys_admin To bind mount /opt/usr/media, /opt/usr/apps from user session + +if [ -e "/usr/bin/session-bind" ] +then /usr/sbin/setcap cap_sys_admin=ei /usr/bin/session-bind +fi + # TODO: MOVE TO OTHER SCRIPT OR REMOVE # Requested by sooyeon.kim@samsung.com if [ -e "/etc/skel/share/.voice" ]