SELinux policy for /dev/sys/block/by-name/rootdisk
Signed-off-by: Jaegeuk Kim <jaegeuk@google.com> Change-Id: I550dfb5649ccb5ca61ea5abbf730bd84756f047e
This commit is contained in:
parent
7bde36e94e
commit
be66c59171
5 changed files with 9 additions and 0 deletions
|
@ -56,6 +56,7 @@
|
|||
proc_watermark_scale_factor
|
||||
remotelyprovisionedkeypool_service
|
||||
resources_manager_service
|
||||
rootdisk_sysdev
|
||||
selection_toolbar_service
|
||||
snapuserd_proxy_socket
|
||||
supplemental_process_service
|
||||
|
|
|
@ -171,6 +171,7 @@
|
|||
/dev/socket/usap_pool_primary u:object_r:zygote_socket:s0
|
||||
/dev/socket/usap_pool_secondary u:object_r:zygote_socket:s0
|
||||
/dev/spdif_out.* u:object_r:audio_device:s0
|
||||
/dev/sys/block/by-name/rootdisk(/.*)? u:object_r:rootdisk_sysdev:s0
|
||||
/dev/sys/block/by-name/userdata(/.*)? u:object_r:userdata_sysdev:s0
|
||||
/dev/sys/fs/by-name/userdata(/.*)? u:object_r:userdata_sysdev:s0
|
||||
/dev/tty u:object_r:owntty_device:s0
|
||||
|
|
|
@ -121,3 +121,6 @@ type sdcard_block_device, dev_type;
|
|||
|
||||
# Userdata device file for filesystem tunables
|
||||
type userdata_sysdev, dev_type;
|
||||
|
||||
# Root disk file for disk tunables
|
||||
type rootdisk_sysdev, dev_type;
|
||||
|
|
|
@ -625,6 +625,9 @@ allow init fuse:dir { search getattr };
|
|||
# allow filesystem tuning
|
||||
allow init userdata_sysdev:file create_file_perms;
|
||||
|
||||
# allow disk tuning
|
||||
allow init rootdisk_sysdev:file create_file_perms;
|
||||
|
||||
###
|
||||
### neverallow rules
|
||||
###
|
||||
|
|
1
public/rootdisk_sysdev.te
Normal file
1
public/rootdisk_sysdev.te
Normal file
|
@ -0,0 +1 @@
|
|||
allow rootdisk_sysdev sysfs:filesystem associate;
|
Loading…
Reference in a new issue