Skip to content
Snippets Groups Projects
  • Jeff Vander Stoep's avatar
    4b7cf4fb
    Suppress su access to pdx sockets · 4b7cf4fb
    Jeff Vander Stoep authored
    Su runs in permissive mode and denials should be suppressed.
    
    avc: denied { getattr } for scontext=u:r:su:s0
    tcontext=u:object_r:pdx_display_client_endpoint_socket:s0
    tclass=unix_stream_socket permissive=1
    avc: denied { getattr } for scontext=u:r:su:s0
    tcontext=u:object_r:pdx_display_manager_endpoint_socket:s0
    tclass=unix_stream_socket permissive=1
    avc: denied { getattr } for scontext=u:r:su:s0
    tcontext=u:object_r:pdx_display_vsync_endpoint_socket:s0
    tclass=unix_stream_socket permissive=1
    avc: denied { getattr } for scontext=u:r:su:s0
    tcontext=u:object_r:pdx_bufferhub_client_endpoint_socket:s0
    tclass=unix_stream_socket permissive=1
    avc: denied { getattr } for scontext=u:r:su:s0
    tcontext=u:object_r:pdx_performance_client_endpoint_socket:s0
    tclass=unix_stream_socket permissive=1
    
    Bug: 35197529
    Test: policy builds
    Change-Id: Ia643c6e776e5e5bd473d857d523c3be91d32c40a
    4b7cf4fb
    History
    Suppress su access to pdx sockets
    Jeff Vander Stoep authored
    Su runs in permissive mode and denials should be suppressed.
    
    avc: denied { getattr } for scontext=u:r:su:s0
    tcontext=u:object_r:pdx_display_client_endpoint_socket:s0
    tclass=unix_stream_socket permissive=1
    avc: denied { getattr } for scontext=u:r:su:s0
    tcontext=u:object_r:pdx_display_manager_endpoint_socket:s0
    tclass=unix_stream_socket permissive=1
    avc: denied { getattr } for scontext=u:r:su:s0
    tcontext=u:object_r:pdx_display_vsync_endpoint_socket:s0
    tclass=unix_stream_socket permissive=1
    avc: denied { getattr } for scontext=u:r:su:s0
    tcontext=u:object_r:pdx_bufferhub_client_endpoint_socket:s0
    tclass=unix_stream_socket permissive=1
    avc: denied { getattr } for scontext=u:r:su:s0
    tcontext=u:object_r:pdx_performance_client_endpoint_socket:s0
    tclass=unix_stream_socket permissive=1
    
    Bug: 35197529
    Test: policy builds
    Change-Id: Ia643c6e776e5e5bd473d857d523c3be91d32c40a