execute: apply PAM logic only to main process if PermissionsStartOnly is set
authorLennart Poettering <lennart@poettering.net>
Tue, 18 Sep 2012 08:54:23 +0000 (10:54 +0200)
committerLennart Poettering <lennart@poettering.net>
Tue, 18 Sep 2012 08:54:23 +0000 (10:54 +0200)
https://bugs.freedesktop.org/show_bug.cgi?id=54176

TODO
src/core/execute.c

diff --git a/TODO b/TODO
index bdfbffb..8addd6e 100644 (file)
--- a/TODO
+++ b/TODO
@@ -28,8 +28,6 @@ F18:
 
 * Retest multi-seat
 
-* selinux: merge systemd selinux access controls (dwalsh)
-
 Features:
 
 * instantiated target units
index 6e2b5e4..cb703cb 100644 (file)
@@ -1283,7 +1283,7 @@ int exec_spawn(ExecCommand *command,
                 umask(context->umask);
 
 #ifdef HAVE_PAM
-                if (context->pam_name && username) {
+                if (apply_permissions && context->pam_name && username) {
                         err = setup_pam(context->pam_name, username, uid, context->tty_path, &pam_env, fds, n_fds);
                         if (err < 0) {
                                 r = EXIT_PAM;