afm-unit.conf: Removes capabilities of applications
authorJosé Bollo <jose.bollo@iot.bzh>
Tue, 10 Oct 2017 09:05:36 +0000 (11:05 +0200)
committerJosé Bollo <jose.bollo@iot.bzh>
Fri, 24 Nov 2017 16:44:57 +0000 (17:44 +0100)
Change-Id: I081e8a8f9ea344d47ae007a4d6c9e72663f82fcf
Signed-off-by: José Bollo <jose.bollo@iot.bzh>
conf/afm-unit-debug.conf.in
conf/afm-unit.conf.in

index 57f934e..3ebcf1d 100644 (file)
@@ -131,6 +131,10 @@ SuccessExitStatus=0 SIGKILL
 PAMName=su
 User=%i
 
+CapabilityBoundingSet=
+AmbientCapabilities=
+SecureBits=no-setuid-fixup-locked
+
 {{#required-permission}}
   {{#urn:AGL:permission::platform:no-oom}}      OOMScoreAdjust=-500             {{/urn:AGL:permission::platform:no-oom}}
   {{#urn:AGL:permission::partner:real-time}}    IOSchedulingClass=realtime      {{/urn:AGL:permission::partner:real-time}}
index 0432ee3..18de05a 100644 (file)
@@ -131,6 +131,10 @@ SuccessExitStatus=0 SIGKILL
 PAMName=su
 User=%i
 
+CapabilityBoundingSet=
+AmbientCapabilities=
+SecureBits=no-setuid-fixup-locked
+
 {{#required-permission}}
   {{#urn:AGL:permission::platform:no-oom}}      OOMScoreAdjust=-500             {{/urn:AGL:permission::platform:no-oom}}
   {{#urn:AGL:permission::partner:real-time}}    IOSchedulingClass=realtime      {{/urn:AGL:permission::partner:real-time}}