Merge "vold: clarify sysfs access"

This commit is contained in:
Treehugger Robot 2018-01-24 21:08:03 +00:00 committed by Gerrit Code Review
commit e2d20c6ef6

View file

@ -11,7 +11,7 @@ allow vold cache_file:lnk_file r_file_perms;
r_dir_file(vold, proc_net) r_dir_file(vold, proc_net)
r_dir_file(vold, sysfs_type) r_dir_file(vold, sysfs_type)
# XXX Label sysfs files with a specific type? # XXX Label sysfs files with a specific type?
allow vold sysfs:file w_file_perms; allow vold sysfs:file w_file_perms; # writing to /sys/*/uevent during coldboot.
allow vold sysfs_dm:file w_file_perms; allow vold sysfs_dm:file w_file_perms;
allow vold sysfs_usb:file w_file_perms; allow vold sysfs_usb:file w_file_perms;
allow vold sysfs_zram_uevent:file w_file_perms; allow vold sysfs_zram_uevent:file w_file_perms;
@ -89,9 +89,6 @@ allow vold domain:{ file lnk_file } r_file_perms;
allow vold domain:process { signal sigkill }; allow vold domain:process { signal sigkill };
allow vold self:global_capability_class_set { sys_ptrace kill }; allow vold self:global_capability_class_set { sys_ptrace kill };
# XXX Label sysfs files with a specific type?
allow vold sysfs:file rw_file_perms;
allow vold kmsg_device:chr_file rw_file_perms; allow vold kmsg_device:chr_file rw_file_perms;
# Run fsck in the fsck domain. # Run fsck in the fsck domain.