Merge "suppress su behavior when running lsof"
This commit is contained in:
commit
8296a542fe
1 changed files with 2 additions and 0 deletions
|
@ -172,6 +172,8 @@ type $1_userfaultfd;
|
|||
type_transition $1 $1:anon_inode $1_userfaultfd "[userfaultfd]";
|
||||
# Allow domain to create/use userfaultfd anon_inode.
|
||||
allow $1 $1_userfaultfd:anon_inode { create ioctl read };
|
||||
# Suppress errors generate during bugreport
|
||||
dontaudit su $1_userfaultfd:anon_inode *;
|
||||
# Other domains may not use userfaultfd anon_inodes created by this domain.
|
||||
neverallow { domain -$1 } $1_userfaultfd:anon_inode *;
|
||||
# This domain may not use userfaultfd anon_inodes created by other domains.
|
||||
|
|
Loading…
Reference in a new issue