From e8610297cf7031e94eb314a2e8c11246f4405403 Mon Sep 17 00:00:00 2001 From: Jacek Bukarewicz Date: Tue, 23 Jun 2015 11:08:48 +0200 Subject: [PATCH] Perform Cynara runtime policy checks by default This change introduces http://tizen.org/privilege/internal/dbus privilege which is supposed to be available only to trusted system resources. Checks for this privilege are used in place of certain allow rules to make security policy more strict. For system bus sending and receiving signals now requires http://tizen.org/privilege/internal/dbus privilege. Requesting name ownership and sending methods is still denied by default. For session bus http://tizen.org/privilege/internal/dbus privilege is now required for requesting name, calling methods, sending and receiving signals. Services are supposed to override these default settings to implement their own security policy. Change-Id: Ifb4a160bf6e0638404e0295a2e4fa3077efd881c Signed-off-by: Jacek Bukarewicz --- bus/session.conf.in | 32 ++++++++++++++++++++++++++------ bus/system.conf.in | 22 ++++++++++++++++------ 2 files changed, 42 insertions(+), 12 deletions(-) diff --git a/bus/session.conf.in b/bus/session.conf.in index 74d9d1f..fa5c232 100644 --- a/bus/session.conf.in +++ b/bus/session.conf.in @@ -17,12 +17,32 @@ - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + - - + - - + - + + + -- 2.1.4