allow lmkd to kill processes.
The previous patch wasn't sufficient. Allow the kill signal. Addresses the following denial: <5>[ 775.819223] type=1400 audit(1393978653.489:18): avc: denied { sigkill } for pid=118 comm="lmkd" scontext=u:r:lmkd:s0 tcontext=u:r:untrusted_app:s0 tclass=process Bug: 13084787 Change-Id: I6af1ed4343b590049809a59e4f2797f6049f12e4
This commit is contained in:
parent
2737ceff23
commit
23a52e6b30
1 changed files with 3 additions and 0 deletions
3
lmkd.te
3
lmkd.te
|
@ -15,3 +15,6 @@ allow lmkd system_server:file write;
|
|||
|
||||
## Writes to /sys/module/lowmemorykiller/parameters/minfree
|
||||
allow lmkd sysfs_lowmemorykiller:file w_file_perms;
|
||||
|
||||
# Send kill signals
|
||||
allow lmkd appdomain:process sigkill;
|
||||
|
|
Loading…
Reference in a new issue