unit.conf: Fix Smack permission on api ws
authorJosé Bollo <jose.bollo@iot.bzh>
Mon, 11 Dec 2017 12:55:10 +0000 (13:55 +0100)
committerJosé Bollo <jose.bollo@iot.bzh>
Mon, 11 Dec 2017 12:55:10 +0000 (13:55 +0100)
The Smack permission to write on the websocket of the API
must be set to something that allows the communication!

Here the chosen value is *

Change-Id: Ia276219b232e33bd35353d8feb333513b340e75c
Signed-off-by: José Bollo <jose.bollo@iot.bzh>
conf/unit/afm-unit-debug.conf.in
conf/unit/afm-unit.conf.in
conf/unit/generate-unit-conf/provided.inc

index ab1ec79..fbf530a 100644 (file)
@@ -215,6 +215,8 @@ After=user@%i.service
 DefaultDependencies=no
 [Socket]
 SmackLabel=*
+SmackLabelIPIn=*
+SmackLabelIPOut=*
 ListenStream=/run/user/%i/apis/ws/{{name}}
 FileDescriptorName={{name}}
 Service=afm-{{#required-permission.urn:AGL:permission::public:hidden}}service{{/required-permission.urn:AGL:permission::public:hidden}}{{^required-permission.urn:AGL:permission::public:hidden}}appli{{/required-permission.urn:AGL:permission::public:hidden}}-{{:id}}--{{:ver}}--{{:#target}}@%i.service
index ad5ecd7..1824358 100644 (file)
@@ -215,6 +215,8 @@ After=user@%i.service
 DefaultDependencies=no
 [Socket]
 SmackLabel=*
+SmackLabelIPIn=*
+SmackLabelIPOut=*
 ListenStream=/run/user/%i/apis/ws/{{name}}
 FileDescriptorName={{name}}
 Service=afm-{{#required-permission.urn:AGL:permission::public:hidden}}service{{/required-permission.urn:AGL:permission::public:hidden}}{{^required-permission.urn:AGL:permission::public:hidden}}appli{{/required-permission.urn:AGL:permission::public:hidden}}-{{:id}}--{{:ver}}--{{:#target}}@%i.service
index 96ac72c..37ed8c4 100644 (file)
@@ -19,6 +19,8 @@ DefaultDependencies=no
 
 [Socket]
 SmackLabel=*
+SmackLabelIPIn=*
+SmackLabelIPOut=*
 ListenStream=USER_RUN_DIR/apis/ws/{{name}}
 FileDescriptorName={{name}}