Allow all domains to read /dev symlinks.
Change-Id: I448a5553937a98775178b94f289ccb45ae862876 Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
This commit is contained in:
parent
62508bf498
commit
0e856a02cb
4 changed files with 1 additions and 9 deletions
7
cts.te
7
cts.te
|
@ -23,13 +23,6 @@ allow appdomain file_type:dir_file_class_set getattr;
|
|||
allow appdomain dev_type:dir_file_class_set getattr;
|
||||
allow appdomain fs_type:dir_file_class_set getattr;
|
||||
|
||||
# Accesses to apk_tmp_file and shell_data_file
|
||||
allow appdomain apk_tmp_file:file rw_file_perms;
|
||||
allow appdomain shell_data_file:file r_file_perms;
|
||||
|
||||
# Read permission over link file to devices.
|
||||
allow appdomain dev_type:lnk_file read;
|
||||
|
||||
# Tries to open /dev/alarm for writing but expects failure.
|
||||
dontaudit appdomain alarm_device:chr_file write;
|
||||
|
||||
|
|
|
@ -40,6 +40,7 @@ allow domain rootfs:lnk_file { read getattr };
|
|||
|
||||
# Device accesses.
|
||||
allow domain device:dir search;
|
||||
allow domain dev_type:lnk_file read;
|
||||
allow domain devpts:dir search;
|
||||
allow domain device:file read;
|
||||
allow domain socket_device:dir search;
|
||||
|
|
1
rild.te
1
rild.te
|
@ -22,7 +22,6 @@ allow rild bluetooth_efs_file:file r_file_perms;
|
|||
allow rild bluetooth_efs_file:dir r_dir_perms;
|
||||
allow rild radio_data_file:dir r_dir_perms;
|
||||
allow rild radio_data_file:file rw_file_perms;
|
||||
allow rild radio_device:lnk_file r_file_perms;
|
||||
allow rild sdcard_type:dir r_dir_perms;
|
||||
allow rild system_data_file:dir create_dir_perms;
|
||||
allow rild system_data_file:file create_file_perms;
|
||||
|
|
1
vold.te
1
vold.te
|
@ -7,7 +7,6 @@ typeattribute vold mlstrustedsubject;
|
|||
allow vold system_file:file x_file_perms;
|
||||
allow vold block_device:dir create_dir_perms;
|
||||
allow vold block_device:blk_file create_file_perms;
|
||||
allow vold block_device:lnk_file read;
|
||||
allow vold devpts:chr_file rw_file_perms;
|
||||
allow vold rootfs:dir mounton;
|
||||
allow vold sdcard_type:dir mounton;
|
||||
|
|
Loading…
Reference in a new issue