Merge "vold: explicitly specify capabilities" am: 4af861b631
Original change: https://android-review.googlesource.com/c/platform/system/vold/+/2371428 Change-Id: Iafe087f3d1dd180069621cc9539803a4dda1bdda Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
This commit is contained in:
commit
8b23e23987
1 changed files with 2 additions and 0 deletions
2
vold.rc
2
vold.rc
|
@ -7,3 +7,5 @@ service vold /system/bin/vold \
|
||||||
shutdown critical
|
shutdown critical
|
||||||
group root reserved_disk
|
group root reserved_disk
|
||||||
reboot_on_failure reboot,vold-failed
|
reboot_on_failure reboot,vold-failed
|
||||||
|
# CAP_SETGID, CAP_SETUID, CAP_SYS_RESOURCE are not used by the vold itself, but instead are used by the /system/bin/sdcard that vold execs
|
||||||
|
capabilities CHOWN DAC_OVERRIDE DAC_READ_SEARCH FOWNER FSETID KILL MKNOD NET_ADMIN SYS_ADMIN SYS_CHROOT SYS_NICE SYS_PTRACE BLOCK_SUSPEND SETGID SETUID SYS_RESOURCE
|
||||||
|
|
Loading…
Reference in a new issue