From 8aa75193662d0e18d7c21ee9d546b7f3c8b8bc14 Mon Sep 17 00:00:00 2001 From: Lennart Poettering Date: Thu, 11 Jul 2013 01:56:12 +0200 Subject: core: grant user@.service instances write access to their own cgroup --- src/core/execute.c | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) diff --git a/src/core/execute.c b/src/core/execute.c index cbeb0caf26..50d2d49ba8 100644 --- a/src/core/execute.c +++ b/src/core/execute.c @@ -1258,6 +1258,23 @@ int exec_spawn(ExecCommand *command, } } +#ifdef HAVE_PAM + if (cgroup_path && context->user && context->pam_name) { + err = cg_set_task_access(SYSTEMD_CGROUP_CONTROLLER, cgroup_path, 0644, uid, gid); + if (err < 0) { + r = EXIT_CGROUP; + goto fail_child; + } + + + err = cg_set_group_access(SYSTEMD_CGROUP_CONTROLLER, cgroup_path, 0755, uid, gid); + if (err < 0) { + r = EXIT_CGROUP; + goto fail_child; + } + } +#endif + if (apply_permissions) { err = enforce_groups(context, username, gid); if (err < 0) { -- cgit v1.2.3-54-g00ecf