Skip to content
Snippets Groups Projects
  • Nick Kralevich's avatar
    4a580cca
    Fix lock logspam and remove domain_deprecated rule · 4a580cca
    Nick Kralevich authored
    Remove system_file:file { lock ioctl } from domain_deprecated. The only
    domains triggering this were dex2oat and netd, which are fixed in this
    change.
    
    Addresses the following logspam similar to:
    
      avc: granted { lock } for comm="iptables"
      path="/system/etc/xtables.lock" dev="sda22" ino=3745
      scontext=u:r:netd:s0 tcontext=u:object_r:system_file:s0 tclass=file
    
      avc: granted { lock } for comm="dex2oat"
      path="/system/framework/arm/boot-okhttp.art" dev="dm-0" ino=1295
      scontext=u:r:dex2oat:s0 tcontext=u:object_r:system_file:s0 tclass=file
    
    Test: device boots and no obvious problems.
    Bug: 28760354
    Bug: 36879751
    Change-Id: Iac851c0e49a52ce4000fdfe16e68c17ff819693f
    4a580cca
    History
    Fix lock logspam and remove domain_deprecated rule
    Nick Kralevich authored
    Remove system_file:file { lock ioctl } from domain_deprecated. The only
    domains triggering this were dex2oat and netd, which are fixed in this
    change.
    
    Addresses the following logspam similar to:
    
      avc: granted { lock } for comm="iptables"
      path="/system/etc/xtables.lock" dev="sda22" ino=3745
      scontext=u:r:netd:s0 tcontext=u:object_r:system_file:s0 tclass=file
    
      avc: granted { lock } for comm="dex2oat"
      path="/system/framework/arm/boot-okhttp.art" dev="dm-0" ino=1295
      scontext=u:r:dex2oat:s0 tcontext=u:object_r:system_file:s0 tclass=file
    
    Test: device boots and no obvious problems.
    Bug: 28760354
    Bug: 36879751
    Change-Id: Iac851c0e49a52ce4000fdfe16e68c17ff819693f