Change attribute for connmand and set uid/gid into service 60/97160/1 submit/tizen_3.0/20161114.042815 submit/tizen_3.0/20161115.065431
authorhyunuktak <hyunuk.tak@samsung.com>
Tue, 30 Aug 2016 05:08:16 +0000 (14:08 +0900)
committerSeonah Moon <seonah1.moon@samsung.com>
Fri, 11 Nov 2016 09:15:27 +0000 (18:15 +0900)
Change-Id: I7c89d697792aff2521a31d1772e696c19313fc44
Signed-off-by: hyunuktak <hyunuk.tak@samsung.com>
packaging/connman.spec
src/connman.service.in
vpn/connman-vpn.service.in

index b37b135..0f2e5fe 100755 (executable)
@@ -208,14 +208,14 @@ systemctl daemon-reload
 
 %files
 %manifest connman.manifest
-%attr(500,root,root) %{_sbindir}/*
+%attr(755,root,root) %{_sbindir}/*
 %attr(500,root,root) %{_bindir}/connmanctl
-%attr(600,root,root) /%{_localstatedir}/lib/connman/settings
+%attr(600,network_fw,network_fw) /%{_localstatedir}/lib/connman/settings
 #%{_libdir}/connman/plugins/*.so
 %attr(644,root,root) %{_datadir}/dbus-1/system-services/*
 #%{_datadir}/dbus-1/services/*
 %{_sysconfdir}/dbus-1/system.d/*
-%attr(644,root,root) %{_sysconfdir}/connman/main.conf
+%attr(644,network_fw,network_fw) %{_sysconfdir}/connman/main.conf
 %{_sysconfdir}/dbus-1/system.d/*.conf
 %attr(644,root,root) %{_libdir}/systemd/system/connman.service
 %attr(644,root,root) %{_libdir}/systemd/system/multi-user.target.wants/connman.service
index 3bc442a..003b110 100755 (executable)
@@ -9,9 +9,9 @@ BusName=net.connman
 Restart=on-failure
 SmackProcessLabel=System
 ExecStart=@sbindir@/connmand -n --noplugin vpn
+User=network_fw
+Group=network_fw
 StandardOutput=null
-CapabilityBoundingSet=~CAP_MAC_ADMIN
-CapabilityBoundingSet=~CAP_MAC_OVERRIDE
 
 [Install]
 WantedBy=multi-user.target
index 6cc59cb..eb75ae4 100755 (executable)
@@ -8,9 +8,9 @@ Type=dbus
 BusName=net.connman.vpn
 SmackProcessLabel=System
 ExecStart=@sbindir@/connman-vpnd -n
+User=network_fw
+Group=network_fw
 StandardOutput=null
-CapabilityBoundingSet=~CAP_MAC_ADMIN
-CapabilityBoundingSet=~CAP_MAC_OVERRIDE
 
 [Install]
 WantedBy=multi-user.target