unit.conf: Remove unset of capabilities
authorJosé Bollo <jose.bollo@iot.bzh>
Tue, 21 Nov 2017 10:39:44 +0000 (11:39 +0100)
committerJosé Bollo <jose.bollo@iot.bzh>
Fri, 24 Nov 2017 16:44:57 +0000 (17:44 +0100)
Remove the unsetting of capabilities because it
currently breaks the image. To be reworked.

Change-Id: I69a1d9c23f463a36edebb7993aa94fae14fb60e8
Signed-off-by: José Bollo <jose.bollo@iot.bzh>
conf/afm-unit-debug.conf.in
conf/afm-unit.conf.in
conf/generate-unit-conf/service.inc

index 8e6fbed..a770fbc 100644 (file)
@@ -122,8 +122,8 @@ SuccessExitStatus=0 SIGKILL
 #PAMName=su
 User=%i
 Slice=user-%i.slice
-CapabilityBoundingSet=
-AmbientCapabilities=
+#CapabilityBoundingSet=
+#AmbientCapabilities=
 {{#required-permission.urn:AGL:permission::platform:no-oom}}OOMScoreAdjust=-500{{/required-permission.urn:AGL:permission::platform:no-oom}}
 {{#required-permission.urn:AGL:permission::partner:real-time}}IOSchedulingClass=realtime{{/required-permission.urn:AGL:permission::partner:real-time}}
 {{#required-permission.urn:AGL:permission::public:display}}SupplementaryGroups=display{{/required-permission.urn:AGL:permission::public:display}}
index 1e95769..11ad15a 100644 (file)
@@ -122,8 +122,8 @@ SuccessExitStatus=0 SIGKILL
 #PAMName=su
 User=%i
 Slice=user-%i.slice
-CapabilityBoundingSet=
-AmbientCapabilities=
+#CapabilityBoundingSet=
+#AmbientCapabilities=
 {{#required-permission.urn:AGL:permission::platform:no-oom}}OOMScoreAdjust=-500{{/required-permission.urn:AGL:permission::platform:no-oom}}
 {{#required-permission.urn:AGL:permission::partner:real-time}}IOSchedulingClass=realtime{{/required-permission.urn:AGL:permission::partner:real-time}}
 {{#required-permission.urn:AGL:permission::public:display}}SupplementaryGroups=display{{/required-permission.urn:AGL:permission::public:display}}
index f2341d1..21e16e3 100644 (file)
@@ -53,8 +53,8 @@ SuccessExitStatus=0 SIGKILL
 User=%i
 Slice=user-%i.slice
 
-CapabilityBoundingSet=
-AmbientCapabilities=
+#CapabilityBoundingSet=
+#AmbientCapabilities=
 
 ON_PERM(:platform:no-oom,   OOMScoreAdjust=-500)
 ON_PERM(:partner:real-time, IOSchedulingClass=realtime)