installd: r_dir_file(installd, system_file) am: 68f233648e
am: b8b0d3746f
am: 24176ec819
am: 5bfb4b3ce8
Change-Id: I4f4e568c4eb4bbe55577c20b157a79fa64f5ab65
This commit is contained in:
commit
cbefe07f1c
2 changed files with 31 additions and 3 deletions
|
@ -41,9 +41,35 @@ auditallow domain_deprecated device:file read;
|
|||
allow domain_deprecated system_file:dir r_dir_perms;
|
||||
allow domain_deprecated system_file:file r_file_perms;
|
||||
allow domain_deprecated system_file:lnk_file r_file_perms;
|
||||
auditallow { domain_deprecated -appdomain -init -rild -surfaceflinger -system_server -zygote } system_file:dir { open read ioctl lock }; # search getattr in domain
|
||||
auditallow { domain_deprecated -appdomain -init -rild -surfaceflinger -system_server -zygote } system_file:file { ioctl lock }; # read open getattr in domain
|
||||
auditallow { domain_deprecated -appdomain -init -rild -surfaceflinger -system_server -zygote } system_file:lnk_file { getattr open ioctl lock }; # read in domain
|
||||
auditallow {
|
||||
domain_deprecated
|
||||
-appdomain
|
||||
-init
|
||||
-installd
|
||||
-rild
|
||||
-surfaceflinger
|
||||
-system_server
|
||||
-zygote
|
||||
} system_file:dir { open read ioctl lock }; # search getattr in domain
|
||||
auditallow {
|
||||
domain_deprecated
|
||||
-appdomain
|
||||
-init
|
||||
-rild
|
||||
-surfaceflinger
|
||||
-system_server
|
||||
-zygote
|
||||
} system_file:file { ioctl lock }; # read open getattr in domain
|
||||
auditallow {
|
||||
domain_deprecated
|
||||
-appdomain
|
||||
-init
|
||||
-installd
|
||||
-rild
|
||||
-surfaceflinger
|
||||
-system_server
|
||||
-zygote
|
||||
} system_file:lnk_file { getattr open ioctl lock }; # read in domain
|
||||
|
||||
# Read files already opened under /data.
|
||||
allow domain_deprecated system_data_file:file { getattr read };
|
||||
|
|
|
@ -25,6 +25,8 @@ allow installd mnt_expand_file:dir { search getattr };
|
|||
selinux_check_context(installd)
|
||||
|
||||
r_dir_file(installd, rootfs)
|
||||
# Scan through APKs in /system/app and /system/priv-app
|
||||
r_dir_file(installd, system_file)
|
||||
|
||||
# Search /data/app-asec and stat files in it.
|
||||
allow installd asec_image_file:dir search;
|
||||
|
|
Loading…
Reference in a new issue