Skip to content
Snippets Groups Projects
  • Jeff Vander Stoep's avatar
    1e1a3f7c
    Annotate denials · 1e1a3f7c
    Jeff Vander Stoep authored
    There is a race condition between when /data is mounted
    and when processes attempt to access it. Attempting to access
    /data before it's mounted causes an selinux denial. Attribute
    these denials to a bug.
    
    07-04 23:48:53.646   503   503 I auditd  : type=1400 audit(0.0:7): avc:
    denied { search } for comm="surfaceflinger" name="/" dev="sda35" ino=2
    scontext=u:r:surfaceflinger:s0 tcontext=u:object_r:unlabeled:s0
    tclass=dir permissive=0
    07-15 17:41:18.100   582   582 I auditd  : type=1400 audit(0.0:4): avc:
    denied { search } for comm="BootAnimation" name="/" dev="sda35" ino=2
    scontext=u:r:bootanim:s0 tcontext=u:object_r:unlabeled:s0 tclass=dir
    permissive=0
    
    Bug: 68864350
    Test: build
    Change-Id: I07f751d54b854bdc72f3e5166442a5e21b3a9bf5
    1e1a3f7c
    History
    Annotate denials
    Jeff Vander Stoep authored
    There is a race condition between when /data is mounted
    and when processes attempt to access it. Attempting to access
    /data before it's mounted causes an selinux denial. Attribute
    these denials to a bug.
    
    07-04 23:48:53.646   503   503 I auditd  : type=1400 audit(0.0:7): avc:
    denied { search } for comm="surfaceflinger" name="/" dev="sda35" ino=2
    scontext=u:r:surfaceflinger:s0 tcontext=u:object_r:unlabeled:s0
    tclass=dir permissive=0
    07-15 17:41:18.100   582   582 I auditd  : type=1400 audit(0.0:4): avc:
    denied { search } for comm="BootAnimation" name="/" dev="sda35" ino=2
    scontext=u:r:bootanim:s0 tcontext=u:object_r:unlabeled:s0 tclass=dir
    permissive=0
    
    Bug: 68864350
    Test: build
    Change-Id: I07f751d54b854bdc72f3e5166442a5e21b3a9bf5