SELinux policy: let adbd drop Linux capabilities.

Change-Id: Id41891b89c7b067919cbda06ab97d5eff2ad044f
This commit is contained in:
Alex Klyubin 2013-05-09 17:03:16 -07:00
parent 77ec892be6
commit 3b9fd5ffcd

View file

@ -3,7 +3,7 @@
type adbd, domain, mlstrustedsubject;
allow adbd adb_device:chr_file rw_file_perms;
allow adbd qemu_device:chr_file rw_file_perms;
allow adbd self:capability { net_raw setgid setuid dac_override sys_boot sys_admin };
allow adbd self:capability { net_raw setgid setuid setpcap dac_override sys_boot sys_admin };
allow adbd rootfs:file { r_file_perms entrypoint };
allow adbd init:process sigchld;
allow adbd self:tcp_socket *;