d22987b4da
Motivation: Domain is overly permissive. Start removing permissions from domain and assign them to the domain_deprecated attribute. Domain_deprecated and domain can initially be assigned to all domains. The goal is to not assign domain_deprecated to new domains and to start removing domain_deprecated where it is not required or reassigning the appropriate permissions to the inheriting domain when necessary. Bug: 25433265 Change-Id: I8b11cb137df7bdd382629c98d916a73fe276413c
8 lines
272 B
Text
8 lines
272 B
Text
# The tzdatacheck command run by init.
|
|
type tzdatacheck, domain, domain_deprecated;
|
|
type tzdatacheck_exec, exec_type, file_type;
|
|
|
|
init_daemon_domain(tzdatacheck)
|
|
|
|
allow tzdatacheck zoneinfo_data_file:dir create_dir_perms;
|
|
allow tzdatacheck zoneinfo_data_file:file unlink;
|