Let vold_prepare_subdirs completely clean deleted user data.
am: 254a872cab
Change-Id: I5de455d60678503f72ae8ee2985c5e7fb0c09b79
This commit is contained in:
commit
397c854db6
2 changed files with 3 additions and 2 deletions
|
@ -12,8 +12,8 @@ allow vold_prepare_subdirs self:process setfscreate;
|
|||
allow vold_prepare_subdirs {
|
||||
system_data_file
|
||||
vendor_data_file
|
||||
}:dir { open read write add_name remove_name relabelfrom };
|
||||
allow vold_prepare_subdirs system_data_file:file getattr;
|
||||
}:dir { open read write add_name remove_name rmdir relabelfrom };
|
||||
allow vold_prepare_subdirs system_data_file:file { getattr unlink };
|
||||
allow vold_prepare_subdirs vold_data_file:dir { create open read write search getattr setattr remove_name rmdir relabelto };
|
||||
allow vold_prepare_subdirs vold_data_file:file { getattr unlink };
|
||||
allow vold_prepare_subdirs storaged_data_file:dir { create_dir_perms relabelto };
|
||||
|
|
|
@ -1120,6 +1120,7 @@ neverallow {
|
|||
-system_app
|
||||
-init
|
||||
-installd # for relabelfrom and unlink, check for this in explicit neverallow
|
||||
-vold_prepare_subdirs # For unlink
|
||||
with_asan(`-asan_extract')
|
||||
} system_data_file:file no_w_file_perms;
|
||||
# do not grant anything greater than r_file_perms and relabelfrom unlink
|
||||
|
|
Loading…
Reference in a new issue