<aegis>

  <!-- RFS (Restore Factory Settings) -->
  <request>
    <!-- UID::root needed to start/stop mission control -->
    <!-- dac_* needed to access/delete cached account data owned by user -->
    <!-- GRP::operator needed to zap the ring account config file -->
    <credential name="UID::root" />
    <credential name="CAP::dac_override" />
    <credential name="CAP::dac_read_search" />  
    <credential name="GRP::operator"/>
    <for path="/etc/osso-rfs-scripts/mission-control.sh" />
  </request>

  <!-- CUD (Clear User Data) -->
  <request>
    <!-- UID::root needed to start/stop mission control -->
    <!-- dac_* needed to access/delete cached account data owned by user -->
    <!-- GRP::operator needed to zap the ring account config file -->
    <credential name="UID::root" />
    <credential name="CAP::dac_override" />
    <credential name="CAP::dac_read_search" />  
    <credential name="GRP::operator"/>
    <for path="/etc/osso-cud-scripts/mission-control.sh" />
  </request>

  <!-- Restore from backup -->
  <request>
    <!-- UID::root needed to start/stop mission control -->
    <!-- dac_* needed to access/delete cached account data owned by user -->
    <!-- chown needed to preserver ownership/permissions in backup dir  -->
    <!-- fowner needed to make sure restored user account file permissions -->
    <!-- GRP::operator needed to restore the ring account config perms -->
    <credential name="UID::root" />
    <credential name="GRP::operator"/>
    <credential name="CAP::chown" />
    <credential name="CAP::dac_override" />
    <credential name="CAP::dac_read_search" />  
    <credential name="CAP::fowner" />
    <for path="/usr/share/backup-framework/scripts/mission-control-restore.sh" />
  </request>

  <!-- pre-backup -->
  <request>
    <!-- UID::root needed to start/stop mission control -->
    <!-- dac_* needed to access/delete cached account data owned by user -->
    <!-- chown needed to preserver ownership/permissions in backup dir  -->
    <!-- GRP::operator needed to restore the ring account config perms -->
    <credential name="UID::root" />
    <credential name="GRP::operator"/>
    <credential name="CAP::chown" />
    <credential name="CAP::dac_override" />
    <credential name="CAP::dac_read_search" />  
    <for path="/usr/share/backup-framework/scripts/mission-control-backup.sh" />
  </request> 

</aegis>
