Skip to content
Snippets Groups Projects
Select Git revision
  • android-7.1.2_r28_klist
  • master default protected
  • pie-cts-release
  • pie-vts-release
  • pie-cts-dev
  • oreo-mr1-iot-release
  • sdk-release
  • oreo-m6-s4-release
  • oreo-m4-s12-release
  • pie-release
  • pie-r2-release
  • pie-r2-s1-release
  • oreo-vts-release
  • oreo-cts-release
  • oreo-dev
  • oreo-mr1-dev
  • pie-gsi
  • pie-platform-release
  • pie-dev
  • oreo-cts-dev
  • android-o-mr1-iot-release-1.0.4
  • android-9.0.0_r8
  • android-9.0.0_r7
  • android-9.0.0_r6
  • android-9.0.0_r5
  • android-8.1.0_r46
  • android-8.1.0_r45
  • android-n-iot-release-smart-display-r2
  • android-vts-8.1_r5
  • android-cts-8.1_r8
  • android-cts-8.0_r12
  • android-cts-7.1_r20
  • android-cts-7.0_r24
  • android-o-mr1-iot-release-1.0.3
  • android-cts-9.0_r1
  • android-8.1.0_r43
  • android-8.1.0_r42
  • android-n-iot-release-smart-display
  • android-p-preview-5
  • android-9.0.0_r3
40 results

shell.te

  • Nick Kralevich's avatar
    f8f937a1
    undeprecate /proc/cpuinfo, more shell permissions · f8f937a1
    Nick Kralevich authored
    Access to /proc/cpuinfo was moved to domain_deprecated in commit
    6e3506e1. Restore access to everyone.
    
    Allow the shell user to stat() /dev, and vfsstat() /proc and other
    labeled filesystems such as /system and /data.
    
    Access to /proc/cpuinfo was explicitly granted to bootanim, but is no
    longer required after moving it back to domain.te. Delete the redundant
    entry.
    
    Commit 4e2d2245 restored access to
    /sys/devices/system/cpu for all domains, but forgot to remove the
    redundant entry from bootanim.te. Cleanup the redundant entry.
    
    Addresses the following denials:
    
      avc: denied { getattr } for pid=23648 comm="bionic-unit-tes" name="/" dev="proc" ino=1 scontext=u:r:shell:s0 tcontext=u:object_r:proc:s0 tclass=filesystem permissive=0
      avc: denied { read } for name="cpuinfo" dev="proc" ino=4026533615 scontext=u:r:shell:s0 tcontext=u:object_r:proc_cpuinfo:s0 tclass=file permissive=0
      avc: denied { getattr } for pid=23713 comm="bionic-unit-tes" path="/dev" dev="tmpfs" ino=11405 scontext=u:r:shell:s0 tcontext=u:object_r:device:s0 tclass=dir permissive=0
      avc: denied { getattr } for name="/" dev="mmcblk0p30" ino=2 scontext=u:r:shell:s0 tcontext=u:object_r:labeledfs:s0 tclass=filesystem permissive=0
    
    Bug: 26295417
    Change-Id: Ia85ac91cbd43235c0f8fe0aebafffb8046cc77ec
    f8f937a1
    History
    undeprecate /proc/cpuinfo, more shell permissions
    Nick Kralevich authored
    Access to /proc/cpuinfo was moved to domain_deprecated in commit
    6e3506e1. Restore access to everyone.
    
    Allow the shell user to stat() /dev, and vfsstat() /proc and other
    labeled filesystems such as /system and /data.
    
    Access to /proc/cpuinfo was explicitly granted to bootanim, but is no
    longer required after moving it back to domain.te. Delete the redundant
    entry.
    
    Commit 4e2d2245 restored access to
    /sys/devices/system/cpu for all domains, but forgot to remove the
    redundant entry from bootanim.te. Cleanup the redundant entry.
    
    Addresses the following denials:
    
      avc: denied { getattr } for pid=23648 comm="bionic-unit-tes" name="/" dev="proc" ino=1 scontext=u:r:shell:s0 tcontext=u:object_r:proc:s0 tclass=filesystem permissive=0
      avc: denied { read } for name="cpuinfo" dev="proc" ino=4026533615 scontext=u:r:shell:s0 tcontext=u:object_r:proc_cpuinfo:s0 tclass=file permissive=0
      avc: denied { getattr } for pid=23713 comm="bionic-unit-tes" path="/dev" dev="tmpfs" ino=11405 scontext=u:r:shell:s0 tcontext=u:object_r:device:s0 tclass=dir permissive=0
      avc: denied { getattr } for name="/" dev="mmcblk0p30" ino=2 scontext=u:r:shell:s0 tcontext=u:object_r:labeledfs:s0 tclass=filesystem permissive=0
    
    Bug: 26295417
    Change-Id: Ia85ac91cbd43235c0f8fe0aebafffb8046cc77ec