Add capabilities to pkg db recovery service 87/275687/1
authorIlho Kim <ilho159.kim@samsung.com>
Mon, 30 May 2022 06:55:19 +0000 (15:55 +0900)
committerIlho Kim <ilho159.kim@samsung.com>
Mon, 30 May 2022 06:55:19 +0000 (15:55 +0900)
This service can execute backend(tpk-backend,wgt-backend,unified-backend)
so same capabilities is needed

Change-Id: I8441449049658df805d39203c3d0d823e6704b7f
Signed-off-by: Ilho Kim <ilho159.kim@samsung.com>
tool/pkg-db-recovery.service

index acf6da6..d26e37e 100644 (file)
@@ -8,7 +8,9 @@ After=systemd-tmpfiles-setup.service local-fs.target
 [Service]
 Type=oneshot
 RemainAfterExit=yes
-SmackProcessLabel=System
+SmackProcessLabel=System::Privileged
+Capabilities=cap_chown,cap_dac_override,cap_fowner,cap_mac_override=i
+SecureBits=keep-caps
 ExecStart=/usr/bin/pkg-db-recovery
 
 [Install]