From: hyunuktak Date: Tue, 30 Aug 2016 05:08:16 +0000 (+0900) Subject: Change attribute for connmand and set uid/gid into service X-Git-Tag: submit/tizen_3.0/20161114.042815^0 X-Git-Url: http://review.tizen.org/git/?a=commitdiff_plain;h=refs%2Fchanges%2F60%2F97160%2F1;p=platform%2Fupstream%2Fconnman.git Change attribute for connmand and set uid/gid into service Change-Id: I7c89d697792aff2521a31d1772e696c19313fc44 Signed-off-by: hyunuktak --- diff --git a/packaging/connman.spec b/packaging/connman.spec index b37b135..0f2e5fe 100755 --- a/packaging/connman.spec +++ b/packaging/connman.spec @@ -208,14 +208,14 @@ systemctl daemon-reload %files %manifest connman.manifest -%attr(500,root,root) %{_sbindir}/* +%attr(755,root,root) %{_sbindir}/* %attr(500,root,root) %{_bindir}/connmanctl -%attr(600,root,root) /%{_localstatedir}/lib/connman/settings +%attr(600,network_fw,network_fw) /%{_localstatedir}/lib/connman/settings #%{_libdir}/connman/plugins/*.so %attr(644,root,root) %{_datadir}/dbus-1/system-services/* #%{_datadir}/dbus-1/services/* %{_sysconfdir}/dbus-1/system.d/* -%attr(644,root,root) %{_sysconfdir}/connman/main.conf +%attr(644,network_fw,network_fw) %{_sysconfdir}/connman/main.conf %{_sysconfdir}/dbus-1/system.d/*.conf %attr(644,root,root) %{_libdir}/systemd/system/connman.service %attr(644,root,root) %{_libdir}/systemd/system/multi-user.target.wants/connman.service diff --git a/src/connman.service.in b/src/connman.service.in index 3bc442a..003b110 100755 --- a/src/connman.service.in +++ b/src/connman.service.in @@ -9,9 +9,9 @@ BusName=net.connman Restart=on-failure SmackProcessLabel=System ExecStart=@sbindir@/connmand -n --noplugin vpn +User=network_fw +Group=network_fw StandardOutput=null -CapabilityBoundingSet=~CAP_MAC_ADMIN -CapabilityBoundingSet=~CAP_MAC_OVERRIDE [Install] WantedBy=multi-user.target diff --git a/vpn/connman-vpn.service.in b/vpn/connman-vpn.service.in index 6cc59cb..eb75ae4 100755 --- a/vpn/connman-vpn.service.in +++ b/vpn/connman-vpn.service.in @@ -8,9 +8,9 @@ Type=dbus BusName=net.connman.vpn SmackProcessLabel=System ExecStart=@sbindir@/connman-vpnd -n +User=network_fw +Group=network_fw StandardOutput=null -CapabilityBoundingSet=~CAP_MAC_ADMIN -CapabilityBoundingSet=~CAP_MAC_OVERRIDE [Install] WantedBy=multi-user.target