domain_deprecated: remove tmpfs dir access

am: ca5bb3371d

Change-Id: I185d127216ee72821c64daf31601fdcbe1a9c069
This commit is contained in:
Jeff Vander Stoep 2017-07-06 16:41:20 +00:00 committed by android-build-merger
commit 453f4a51c6
2 changed files with 1 additions and 17 deletions

View file

@ -1,21 +1,5 @@
# rules removed from the domain attribute
# Search /storage/emulated tmpfs mount.
allow { domain_deprecated -installd } tmpfs:dir r_dir_perms;
userdebug_or_eng(`
auditallow {
domain_deprecated
-appdomain
-installd
-recovery
-sdcardd
-surfaceflinger
-system_server
-vold
-zygote
} tmpfs:dir r_dir_perms;
')
# Root fs.
allow domain_deprecated rootfs:dir r_dir_perms;
allow domain_deprecated rootfs:file r_file_perms;

View file

@ -84,7 +84,7 @@ allow dumpstate sysfs_usb:file w_file_perms;
allow dumpstate qtaguid_proc:file r_file_perms;
allow dumpstate debugfs:file r_file_perms;
# df for /storage/emulated needs search
allow dumpstate { storage_file block_device }:dir { search getattr };
allow dumpstate { block_device storage_file tmpfs }:dir { search getattr };
allow dumpstate fuse_device:chr_file getattr;
allow dumpstate { dm_device cache_block_device }:blk_file getattr;