Skip to content
Snippets Groups Projects
  • Jeff Vander Stoep's avatar
    84f96859
    Audit app access to /proc/net/* · 84f96859
    Jeff Vander Stoep authored
    Many processes including third party apps are expected to
    access /proc/net/xt_qtaguid/stats. Give this file a new label
    to avoid spamming the logs and temporarily grant read access to
    all processes.
    
    Read-only permission is adequate for all processes based on unix
    permissions.
    sailfish:/ # ls -laZ /proc/net/xt_qtaguid/stats
    -r--r--r--  1 root net_bw_stats u:object_r:proc_net_xt_qtaguid_stats:s0 stats
    
    Bug: 9496886
    Bug: 68016944
    Bug: 70722355
    Test: Build/flash Sailfish. Browse in Chrome and watch videos in youtube.
        No "denied" or "granted" selinux messages observed in the logs.
    
    Change-Id: I29f1ee806c8149988b9b93a950790d14754927ef
    84f96859
    History
    Audit app access to /proc/net/*
    Jeff Vander Stoep authored
    Many processes including third party apps are expected to
    access /proc/net/xt_qtaguid/stats. Give this file a new label
    to avoid spamming the logs and temporarily grant read access to
    all processes.
    
    Read-only permission is adequate for all processes based on unix
    permissions.
    sailfish:/ # ls -laZ /proc/net/xt_qtaguid/stats
    -r--r--r--  1 root net_bw_stats u:object_r:proc_net_xt_qtaguid_stats:s0 stats
    
    Bug: 9496886
    Bug: 68016944
    Bug: 70722355
    Test: Build/flash Sailfish. Browse in Chrome and watch videos in youtube.
        No "denied" or "granted" selinux messages observed in the logs.
    
    Change-Id: I29f1ee806c8149988b9b93a950790d14754927ef