Revert "Revert "Depend on SmackProcessLabel= to set correct label instead of pam"" 37/193537/1 accepted/tizen_5.5_unified accepted/tizen_5.5_unified_mobile_hotfix accepted/tizen_5.5_unified_wearable_hotfix tizen_5.5_mobile_hotfix tizen_5.5_tv tizen_5.5_wearable_hotfix accepted/tizen/5.5/unified/20191031.015814 accepted/tizen/5.5/unified/mobile/hotfix/20201027.075722 accepted/tizen/5.5/unified/wearable/hotfix/20201027.110804 accepted/tizen/unified/20181130.134737 submit/tizen/20181122.025733 submit/tizen/20181130.022847 submit/tizen_5.5/20191031.000005 submit/tizen_5.5_mobile_hotfix/20201026.185105 submit/tizen_5.5_wearable_hotfix/20201026.184305 tizen_5.5.m2_release
authorKarol Lewandowski <k.lewandowsk@samsung.com>
Wed, 21 Nov 2018 14:37:49 +0000 (15:37 +0100)
committerKarol Lewandowski <k.lewandowsk@samsung.com>
Wed, 21 Nov 2018 14:38:03 +0000 (15:38 +0100)
This reverts commit 31e9e250b73d3f9190a579b262af8bab1384727f.

The problem was in security-config package that removed the service
file during image creation stage.  The removal was caused by change
(SmackProcessLabel=) that didn't match its own "saved" policy.

Change-Id: I4702acf22690e91759edc2da77a6ac46f32fd188

data/tlm-default-login
data/tlm-login
data/tlm-system-login
data/tlm.service

index 8138015..53d6173 100644 (file)
@@ -10,4 +10,3 @@ session         required        pam_systemd.so
 session         required        pam_loginuid.so
 session         required        pam_namespace.so
 session         optional        pam_keyinit.so force revoke
-session         required        pam_smack.so
index 0bc8045..c921924 100644 (file)
@@ -11,4 +11,3 @@ session         required        pam_systemd.so
 session         required        pam_loginuid.so
 session         required        pam_namespace.so
 session         optional        pam_keyinit.so force revoke
-session         required        pam_smack.so
\ No newline at end of file
index 2f7b518..8e247bc 100644 (file)
@@ -8,4 +8,3 @@ session         include         system-auth
 session         required        pam_loginuid.so
 session         required        pam_namespace.so
 session         optional        pam_keyinit.so force revoke
-session         required        pam_smack.so
index 94c5fe0..9001d33 100644 (file)
@@ -4,7 +4,7 @@ After=systemd-user-sessions.service systemd-logind.service
 Requires=dbus.socket
 
 [Service]
-SmackProcessLabel=System
+SmackProcessLabel=User
 ExecStart=/usr/bin/tlm
 CapabilityBoundingSet=~CAP_MAC_ADMIN
 CapabilityBoundingSet=~CAP_MAC_OVERRIDE