SELinux policy: let adbd drop Linux capabilities.
Change-Id: Id41891b89c7b067919cbda06ab97d5eff2ad044f
This commit is contained in:
parent
77ec892be6
commit
3b9fd5ffcd
1 changed files with 1 additions and 1 deletions
2
adbd.te
2
adbd.te
|
@ -3,7 +3,7 @@
|
|||
type adbd, domain, mlstrustedsubject;
|
||||
allow adbd adb_device:chr_file rw_file_perms;
|
||||
allow adbd qemu_device:chr_file rw_file_perms;
|
||||
allow adbd self:capability { net_raw setgid setuid dac_override sys_boot sys_admin };
|
||||
allow adbd self:capability { net_raw setgid setuid setpcap dac_override sys_boot sys_admin };
|
||||
allow adbd rootfs:file { r_file_perms entrypoint };
|
||||
allow adbd init:process sigchld;
|
||||
allow adbd self:tcp_socket *;
|
||||
|
|
Loading…
Reference in a new issue