Revert "Add some groups for user session daemons"
authorRafal Krypa <r.krypa@samsung.com>
Wed, 16 Nov 2016 09:47:49 +0000 (10:47 +0100)
committerŁukasz Stelmach <l.stelmach@samsung.com>
Fri, 26 Jan 2024 16:49:49 +0000 (17:49 +0100)
Security-manager 1.1.16 has made this obsolete.
There is no longer a need for manually adding privilege-related supplementary
groups to user sessions. They will be added by a dedicated NSS plugin:
libnss-security-manager.

This reverts commit 78a648a0611caccdd87a38f99f65ba296608da69.

Change-Id: Ic421a2ee65550762356784b585d2fba8645fbd5c

units/user@.service.m4.in

index ae38195..12960d8 100644 (file)
@@ -22,6 +22,5 @@ TasksMax=infinity
 Environment=DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/%i/dbus/user_bus_socket
 Environment=XDG_RUNTIME_DIR=/run/user/%i
 Capabilities=cap_sys_admin,cap_mac_admin,cap_mac_override,cap_setgid,cap_dac_override=i
-SupplementaryGroups=priv_mediastorage priv_externalstorage priv_message_read priv_mapservice priv_network_get priv_internet
 SecureBits=keep-caps
 TimeoutStartSec=infinity