domain_deprecated: remove tmpfs dir access
am: ca5bb3371d
Change-Id: I185d127216ee72821c64daf31601fdcbe1a9c069
This commit is contained in:
commit
453f4a51c6
2 changed files with 1 additions and 17 deletions
|
@ -1,21 +1,5 @@
|
|||
# rules removed from the domain attribute
|
||||
|
||||
# Search /storage/emulated tmpfs mount.
|
||||
allow { domain_deprecated -installd } tmpfs:dir r_dir_perms;
|
||||
userdebug_or_eng(`
|
||||
auditallow {
|
||||
domain_deprecated
|
||||
-appdomain
|
||||
-installd
|
||||
-recovery
|
||||
-sdcardd
|
||||
-surfaceflinger
|
||||
-system_server
|
||||
-vold
|
||||
-zygote
|
||||
} tmpfs:dir r_dir_perms;
|
||||
')
|
||||
|
||||
# Root fs.
|
||||
allow domain_deprecated rootfs:dir r_dir_perms;
|
||||
allow domain_deprecated rootfs:file r_file_perms;
|
||||
|
|
|
@ -84,7 +84,7 @@ allow dumpstate sysfs_usb:file w_file_perms;
|
|||
allow dumpstate qtaguid_proc:file r_file_perms;
|
||||
allow dumpstate debugfs:file r_file_perms;
|
||||
# df for /storage/emulated needs search
|
||||
allow dumpstate { storage_file block_device }:dir { search getattr };
|
||||
allow dumpstate { block_device storage_file tmpfs }:dir { search getattr };
|
||||
allow dumpstate fuse_device:chr_file getattr;
|
||||
allow dumpstate { dm_device cache_block_device }:blk_file getattr;
|
||||
|
||||
|
|
Loading…
Reference in a new issue