service :set the capabilities
[src/app-framework-main.git] / conf / afm-system-daemon.service
index 80c880f..b14f417 100644 (file)
@@ -8,6 +8,9 @@ Group=afm
 ExecStart=/usr/bin/afm-system-daemon
 Restart=on-failure
 RestartSec=5
+CapabilityBoundingSet=CAP_DAC_OVERRIDE CAP_MAC_OVERRIDE
+SecureBits=keep-caps
+Capabilities=cap_dac_override,cap_mac_override=i
 
 [Install]
 WantedBy=multi-user.target