Skip to content
Snippets Groups Projects
  • Tri Vo's avatar
    62f2842c
    Explicitly label filesystem files in /proc · 62f2842c
    Tri Vo authored
    proc files needed by fwk that were labeled:
    /proc/filesystems -> proc_filesystems
    /proc/mounts -> proc_mounts
    /proc/swaps -> proc_mounts
    
    Removed access to proc label from these domains:
    e2fs, fsck, fsck_untrusted, sdcardd
    
    e2fs: added access to proc_filesystems, proc_mounts, proc_swaps
    fsck: added access to proc_mounts, proc_swaps
    fsck_untrusted: added access to proc_mounts
    sdcardd: added access to proc_filesystems
    vold: added access to proc_filesystems, proc_mounts
    
    Bug: 66199084
    Test: device boots without selinux denials to new labels or proc label.
    Change-Id: If0f19e22074419dab0b3a0c6f3a300ea8cb94523
    62f2842c
    History
    Explicitly label filesystem files in /proc
    Tri Vo authored
    proc files needed by fwk that were labeled:
    /proc/filesystems -> proc_filesystems
    /proc/mounts -> proc_mounts
    /proc/swaps -> proc_mounts
    
    Removed access to proc label from these domains:
    e2fs, fsck, fsck_untrusted, sdcardd
    
    e2fs: added access to proc_filesystems, proc_mounts, proc_swaps
    fsck: added access to proc_mounts, proc_swaps
    fsck_untrusted: added access to proc_mounts
    sdcardd: added access to proc_filesystems
    vold: added access to proc_filesystems, proc_mounts
    
    Bug: 66199084
    Test: device boots without selinux denials to new labels or proc label.
    Change-Id: If0f19e22074419dab0b3a0c6f3a300ea8cb94523