Depend on SmackProcessLabel= to set correct label instead of pam 69/193169/1 accepted/tizen/unified/20181119.013230 submit/tizen/20181116.003516
authorKarol Lewandowski <k.lewandowsk@samsung.com>
Thu, 15 Nov 2018 12:53:55 +0000 (13:53 +0100)
committerKarol Lewandowski <k.lewandowsk@samsung.com>
Thu, 15 Nov 2018 12:53:55 +0000 (13:53 +0100)
pam_smack.so has been removed as for our use-case it is enough to set
appropriate label via systemd SmackProcessLabel.

Change-Id: Ia5f9a9f1e6f2809408b090b8e2805db7968a36a9

data/tlm-default-login
data/tlm-login
data/tlm-system-login
data/tlm.service

index 8138015..53d6173 100644 (file)
@@ -10,4 +10,3 @@ session         required        pam_systemd.so
 session         required        pam_loginuid.so
 session         required        pam_namespace.so
 session         optional        pam_keyinit.so force revoke
-session         required        pam_smack.so
index 0bc8045..c921924 100644 (file)
@@ -11,4 +11,3 @@ session         required        pam_systemd.so
 session         required        pam_loginuid.so
 session         required        pam_namespace.so
 session         optional        pam_keyinit.so force revoke
-session         required        pam_smack.so
\ No newline at end of file
index 2f7b518..8e247bc 100644 (file)
@@ -8,4 +8,3 @@ session         include         system-auth
 session         required        pam_loginuid.so
 session         required        pam_namespace.so
 session         optional        pam_keyinit.so force revoke
-session         required        pam_smack.so
index 94c5fe0..9001d33 100644 (file)
@@ -4,7 +4,7 @@ After=systemd-user-sessions.service systemd-logind.service
 Requires=dbus.socket
 
 [Service]
-SmackProcessLabel=System
+SmackProcessLabel=User
 ExecStart=/usr/bin/tlm
 CapabilityBoundingSet=~CAP_MAC_ADMIN
 CapabilityBoundingSet=~CAP_MAC_OVERRIDE