service :set the capabilities
authorJosé Bollo <jose.bollo@iot.bzh>
Thu, 11 Feb 2016 15:41:57 +0000 (16:41 +0100)
committerJosé Bollo <jose.bollo@iot.bzh>
Thu, 11 Feb 2016 15:41:57 +0000 (16:41 +0100)
Change-Id: I9722d6c6876fd872dccd9cb77f85b208c45e4b51
Signed-off-by: José Bollo <jose.bollo@iot.bzh>
conf/afm-system-daemon.service

index 80c880f..b14f417 100644 (file)
@@ -8,6 +8,9 @@ Group=afm
 ExecStart=/usr/bin/afm-system-daemon
 Restart=on-failure
 RestartSec=5
+CapabilityBoundingSet=CAP_DAC_OVERRIDE CAP_MAC_OVERRIDE
+SecureBits=keep-caps
+Capabilities=cap_dac_override,cap_mac_override=i
 
 [Install]
 WantedBy=multi-user.target