From cee3f687eb37a516239d30dfe35520c92c532c6a Mon Sep 17 00:00:00 2001 From: Tri Vo Date: Wed, 21 Mar 2018 16:37:23 +0000 Subject: [PATCH] Revert "silence innocuous denials to /proc and /sys" This reverts commit 09b1d962eff9e17d05998fa19158c2bb6fe99a01. Reason for revert: bullhead broken Change-Id: Ib4562f944cdc2618cc3ed3beb4f612f0ef8b3223 --- public/domain.te | 11 ----------- public/file.te | 4 ++-- 2 files changed, 2 insertions(+), 13 deletions(-) diff --git a/public/domain.te b/public/domain.te index f602d0884..869d94e8c 100644 --- a/public/domain.te +++ b/public/domain.te @@ -1319,14 +1319,3 @@ neverallow { -zygote } self:capability dac_override; neverallow domain self:capability dac_read_search; - -# If an already existing file is opened with O_CREATE, the kernel might generate -# a false report of a create denial. Silence these denials and make sure that -# inappropriate permissions are not granted. -neverallow domain { - proc_type - sysfs_type -}:dir { add_name create link remove_name rename reparent rmdir write }; - -dontaudit domain proc_type:dir write; -dontaudit domain sysfs_type:dir write; diff --git a/public/file.te b/public/file.te index 9301d8901..0161bca4d 100644 --- a/public/file.te +++ b/public/file.te @@ -83,10 +83,10 @@ type sysfs_net, fs_type, sysfs_type; type sysfs_power, fs_type, sysfs_type; type sysfs_rtc, fs_type, sysfs_type; type sysfs_switch, fs_type, sysfs_type; -type sysfs_usb, fs_type, sysfs_type; +type sysfs_usb, sysfs_type, file_type, mlstrustedobject; type sysfs_wakeup_reasons, fs_type, sysfs_type; type sysfs_fs_ext4_features, sysfs_type, fs_type; -type fs_bpf, fs_type; +type fs_bpf, fs_type, sysfs_type; type configfs, fs_type; # /sys/devices/system/cpu type sysfs_devices_system_cpu, fs_type, sysfs_type;