X-Git-Url: https://gerrit.automotivelinux.org/gerrit/gitweb?p=src%2Fapp-framework-main.git;a=blobdiff_plain;f=conf%2Fafm-unit.conf;h=437d05366a8f87fb06f0c2fb75cba47ab85053c7;hp=0853d11b3921758f66ab0be34f98816596aac513;hb=39d36dfadc1de6a2063e2928f8f8a00683b14a07;hpb=6506c0c80b7542ca97149d9a53d88f5f0b7a0d2d diff --git a/conf/afm-unit.conf b/conf/afm-unit.conf index 0853d11..437d053 100644 --- a/conf/afm-unit.conf +++ b/conf/afm-unit.conf @@ -84,7 +84,6 @@ SmackProcessLabel=User::App::{{id}} {{^urn:AGL:permission::partner:real-time}} RestrictRealtime=on {{/urn:AGL:permission::partner:real-time}} {{#urn:AGL:permission::public:display}} SupplementaryGroups=display {{/urn:AGL:permission::public:display}} {{^urn:AGL:permission::public:syscall:clock}} SystemCallFilter=~@clock {{/urn:AGL:permission::public:syscall:clock}} - {{^urn:AGL:permission::public:internet}} RestrictAddressFamilies=AF_UNIX {{/urn:AGL:permission::public:internet}} {{/required-permission}} %nl @@ -101,7 +100,12 @@ SuccessExitStatus=0 SIGKILL ExecStart=/usr/bin/afb-daemon --port={{:#metadata.http-port}} --random-token \ --rootdir={{:#metadata.install-dir}} \ --workdir={{&#metadata.app-data-dir}}/{{id}} \ - --roothttp=htdocs \ + {{#required-permission.urn:AGL:permission::public:no-htdocs}}\ + --roothttp=. \ + {{/required-permission.urn:AGL:permission::public:no-htdocs}}\ + {{^required-permission.urn:AGL:permission::public:no-htdocs}}\ + --roothttp=htdocs \ + {{/required-permission.urn:AGL:permission::public:no-htdocs}}\ {{#required-permission.urn:AGL:permission::public:applications:read}}\ --alias=/icons:{{:#metadata.icons-dir}} \ {{/required-permission.urn:AGL:permission::public:applications:read}}\ @@ -136,12 +140,12 @@ ExecStart=/usr/bin/afb-daemon \ --rootdir={{:#metadata.install-dir}} \ --workdir={{&#metadata.install-dir}}/{{id}} \ {{^required-permission.urn:AGL:permission::partner:service:no-ws}}\ - --ws-server=unix:%t/bindings/{{:#target}} \ + --ws-server=sd:{{:#target}} \ {{/required-permission.urn:AGL:permission::partner:service:no-ws}}\ {{^required-permission.urn:AGL:permission::partner:service:no-dbus}}\ --dbus-server={{:#target}} \ {{/required-permission.urn:AGL:permission::partner:service:no-dbus}}\ - --no-httpd + --no-httpd {{^required-permission.urn:AGL:permission::partner:service:no-ws}} @@ -157,6 +161,7 @@ ExecStart=/usr/bin/afb-daemon \ [socket] SmackLabel=* ListenStream=%t/bindings/{{:#target}} +FileDescriptorName={{:#target}} {{/required-permission.urn:AGL:permission::partner:service:no-ws}}