Skip to content
Snippets Groups Projects
  • Tri Vo's avatar
    04fb82f2
    /proc, /sys access from uncrypt, update_engine, postinstall_dexopt · 04fb82f2
    Tri Vo authored
    New types:
    1. proc_random
    2. sysfs_dt_firmware_android
    
    Labeled:
    1. /proc/sys/kernel/random as proc_random.
    2. /sys/firmware/devicetree/base/firmware/android/{compatible, fstab,
    vbmeta} as sysfs_dt_firmware_android.
    
    Changed access:
    1. uncrypt, update_engine, postinstall_dexopt have access to generic proc
    and sysfs labels removed.
    2. appropriate permissions were added to uncrypt, update_engine,
    update_engine_common, postinstall_dexopt.
    
    Bug: 67416435
    Bug: 67416336
    Test: fake ota go/manual-ab-ota runs without denials
    Test: adb sideload runs without denials to new types
    Change-Id: Id31310ceb151a18652fcbb58037a0b90c1f6505a
    04fb82f2
    History
    /proc, /sys access from uncrypt, update_engine, postinstall_dexopt
    Tri Vo authored
    New types:
    1. proc_random
    2. sysfs_dt_firmware_android
    
    Labeled:
    1. /proc/sys/kernel/random as proc_random.
    2. /sys/firmware/devicetree/base/firmware/android/{compatible, fstab,
    vbmeta} as sysfs_dt_firmware_android.
    
    Changed access:
    1. uncrypt, update_engine, postinstall_dexopt have access to generic proc
    and sysfs labels removed.
    2. appropriate permissions were added to uncrypt, update_engine,
    update_engine_common, postinstall_dexopt.
    
    Bug: 67416435
    Bug: 67416336
    Test: fake ota go/manual-ab-ota runs without denials
    Test: adb sideload runs without denials to new types
    Change-Id: Id31310ceb151a18652fcbb58037a0b90c1f6505a