summaryrefslogtreecommitdiff
path: root/src
diff options
context:
space:
mode:
authorhyunuktak <hyunuk.tak@samsung.com>2016-06-09 15:43:58 +0900
committerhyunuktak <hyunuk.tak@samsung.com>2016-06-09 15:44:00 +0900
commitfe5392acf9111aed0f479a56d6953fbc7c6754da (patch)
treeabe4155d826d2a39ae2749a0d0c433e0721c9be7 /src
parent0ea98e0cff37f5a63783a65c84cc5945466b9024 (diff)
downloadconnman-fe5392acf9111aed0f479a56d6953fbc7c6754da.tar.gz
connman-fe5392acf9111aed0f479a56d6953fbc7c6754da.tar.bz2
connman-fe5392acf9111aed0f479a56d6953fbc7c6754da.zip
Remove capability and Change from dbus to systemd for vpn service
Change-Id: I7ef5583cfc148b4835abec4bf57ad76369ed9b8e Signed-off-by: hyunuktak <hyunuk.tak@samsung.com>
Diffstat (limited to 'src')
-rwxr-xr-xsrc/connman.service.in2
-rw-r--r--src/connman_tv.service.in2
-rwxr-xr-xsrc/net.connman.service.in2
3 files changed, 5 insertions, 1 deletions
diff --git a/src/connman.service.in b/src/connman.service.in
index adf7a62a..503ec455 100755
--- a/src/connman.service.in
+++ b/src/connman.service.in
@@ -9,6 +9,8 @@ BusName=net.connman
Restart=on-failure
ExecStart=@sbindir@/connmand -n --noplugin vpn
StandardOutput=null
+CapabilityBoundingSet=~CAP_MAC_ADMIN
+CapabilityBoundingSet=~CAP_MAC_OVERRIDE
[Install]
WantedBy=multi-user.target
diff --git a/src/connman_tv.service.in b/src/connman_tv.service.in
index 2922aa86..c0328467 100644
--- a/src/connman_tv.service.in
+++ b/src/connman_tv.service.in
@@ -7,6 +7,8 @@ BusName=net.connman
RemainAfterExit=yes
ExecStartPre=/usr/bin/dbus-send --system --dest=net.netconfig / net.netconfig.auto.activate
ExecStart=/usr/sbin/connmand --noplugin vpn
+CapabilityBoundingSet=~CAP_MAC_ADMIN
+CapabilityBoundingSet=~CAP_MAC_OVERRIDE
[Install]
WantedBy=multi-user.target
diff --git a/src/net.connman.service.in b/src/net.connman.service.in
index f7f6a7c0..9679c1be 100755
--- a/src/net.connman.service.in
+++ b/src/net.connman.service.in
@@ -1,5 +1,5 @@
[D-BUS Service]
Name=net.connman
-Exec=@sbindir@/connmand -n
+Exec=/bin/false
User=root
SystemdService=connman.service