Skip to content
Snippets Groups Projects
  • Nick Kralevich's avatar
    829a7493
    domain_deprecated.te: Exclude recovery from auditallow for /cache/recovery · 829a7493
    Nick Kralevich authored
    Recovery uses /cache/recovery. Exclude it from auditallow coverage.
    
    Addresses the following SELinux log spam:
    
      avc:  granted  { search } for  pid=323 comm="recovery" name="recovery" dev="mmcblk0p38" ino=12 scontext=u:r:recovery:s0 tcontext=u:object_r:cache_recovery_file:s0 tclass=dir
      avc:  granted  { read } for  pid=323 comm="recovery" name="block.map" dev="mmcblk0p38" ino=26 scontext=u:r:recovery:s0 tcontext=u:object_r:cache_recovery_file:s0 tclass=file
      avc:  granted  { getattr } for  pid=323 comm="recovery" path="/cache/recovery/block.map" dev="mmcblk0p38" ino=26 scontext=u:r:recovery:s0 tcontext=u:object_r:cache_recovery_file:s0 tclass=file
    
    Change-Id: Ib6c7b44ac23fccaf2ea506429fb760ee85e87c76
    829a7493
    History
    domain_deprecated.te: Exclude recovery from auditallow for /cache/recovery
    Nick Kralevich authored
    Recovery uses /cache/recovery. Exclude it from auditallow coverage.
    
    Addresses the following SELinux log spam:
    
      avc:  granted  { search } for  pid=323 comm="recovery" name="recovery" dev="mmcblk0p38" ino=12 scontext=u:r:recovery:s0 tcontext=u:object_r:cache_recovery_file:s0 tclass=dir
      avc:  granted  { read } for  pid=323 comm="recovery" name="block.map" dev="mmcblk0p38" ino=26 scontext=u:r:recovery:s0 tcontext=u:object_r:cache_recovery_file:s0 tclass=file
      avc:  granted  { getattr } for  pid=323 comm="recovery" path="/cache/recovery/block.map" dev="mmcblk0p38" ino=26 scontext=u:r:recovery:s0 tcontext=u:object_r:cache_recovery_file:s0 tclass=file
    
    Change-Id: Ib6c7b44ac23fccaf2ea506429fb760ee85e87c76