Merge "Allow microdroid_manager to BLKFLSBUF on the instance disk" am: 03b3b18c70
am: 2f94a92cdc
am: 598983f832
Original change: https://android-review.googlesource.com/c/platform/system/sepolicy/+/1974319 Change-Id: I82003c408ad4952167644e7c0c84a75f7bd76855
This commit is contained in:
commit
6308e3fa7b
1 changed files with 5 additions and 0 deletions
|
@ -14,6 +14,11 @@ allow microdroid_manager vd_device:blk_file rw_file_perms;
|
|||
# microdroid_manager verifies DM-verity mounted APK payload
|
||||
allow microdroid_manager dm_device:blk_file r_file_perms;
|
||||
|
||||
# Allow microdroid_manager to do blkflsbuf on instance disk image. The ioctl
|
||||
# requires sys_admin cap as well.
|
||||
allowxperm microdroid_manager vd_device:blk_file ioctl BLKFLSBUF;
|
||||
allow microdroid_manager self:global_capability_class_set sys_admin;
|
||||
|
||||
# Allow microdroid_manager to start payload tasks
|
||||
domain_auto_trans(microdroid_manager, microdroid_app_exec, microdroid_app)
|
||||
domain_auto_trans(microdroid_manager, compos_exec, compos)
|
||||
|
|
Loading…
Reference in a new issue