Fix shared libraries file permissions

Updated shared library files permission from
/usr/lib/systemd/system/ to be non group-writable,
to fix openscap security violation.
Verified installation is successful in AIO-SX and
Standard 2+2 system configurations.
Ran successfully "taskset" command to check current
affinity to platforms CPUs.

Story: 2008037
Task: 40694

Change-Id: If8d7d3becba073ee827e988f1e651a9c8d31d773
Signed-off-by: Carmen Rata <carmen.rata@windriver.com>
This commit is contained in:
Carmen Rata 2020-10-22 23:05:08 -04:00
parent 31f2d4d5cf
commit ddd40f08f2
2 changed files with 3 additions and 3 deletions

View File

@ -57,7 +57,7 @@ install -p -D -m 700 scripts/init.d/logmgmt %{buildroot}%{local_etc_initd}/logmg
install -d -m 755 %{buildroot}%{local_etc_pmond}
install -p -D -m 644 scripts/pmon.d/logmgmt %{buildroot}%{local_etc_pmond}/logmgmt
install -p -D -m 664 scripts/etc/systemd/system/logmgmt.service %{buildroot}%{_unitdir}/logmgmt.service
install -p -D -m 644 scripts/etc/systemd/system/logmgmt.service %{buildroot}%{_unitdir}/logmgmt.service
%post
/usr/bin/systemctl enable logmgmt.service >/dev/null 2>&1

View File

@ -29,5 +29,5 @@ install:
install -p -D -m 755 topology $(BINDIR)/topology
install -p -D -m 644 worker_reserved.conf $(PLATFORMCONFDIR)/worker_reserved.conf
install -p -D -m 755 worker-goenabled.sh $(GOENABLEDDIR)/worker-goenabled.sh
install -p -D -m 664 affine-platform.sh.service $(SYSTEMDDIR)/affine-platform.sh.service
install -p -D -m 664 affine-tasks.service $(SYSTEMDDIR)/affine-tasks.service
install -p -D -m 644 affine-platform.sh.service $(SYSTEMDDIR)/affine-platform.sh.service
install -p -D -m 644 affine-tasks.service $(SYSTEMDDIR)/affine-tasks.service