Merge "Ensure taking a bugreport generates no denials."
This commit is contained in:
commit
dc60253988
1 changed files with 6 additions and 0 deletions
|
@ -264,6 +264,12 @@ allow dumpstate self:netlink_socket create_socket_perms_no_ioctl;
|
|||
# newer kernels (e.g. 4.4) have a new class for sockets
|
||||
allow dumpstate self:netlink_generic_socket create_socket_perms_no_ioctl;
|
||||
|
||||
# Allow dumpstate to run ss
|
||||
allow dumpstate { domain pdx_channel_socket_type pdx_endpoint_socket_type }:socket_class_set getattr;
|
||||
|
||||
# For when dumpstate runs df
|
||||
dontaudit dumpstate mnt_vendor_file:dir search;
|
||||
|
||||
# Allow dumpstate to kill vendor dumpstate service by init
|
||||
set_prop(dumpstate, ctl_dumpstate_prop)
|
||||
|
||||
|
|
Loading…
Reference in a new issue