Skip to content
Snippets Groups Projects
  • Jeff Vander Stoep's avatar
    a12aad45
    domain_deprecated: remove rootfs access · a12aad45
    Jeff Vander Stoep authored
    Grant audited permissions collected in logs.
    
    tcontext=platform_app
    avc: granted { getattr } for comm=496E666C6174657254687265616420
    path="/" dev="dm-0" ino=2 scontext=u:r:platform_app:s0:c512,c768
    tcontext=u:object_r:rootfs:s0 tclass=dir
    
    tcontext=system_app
    avc: granted { getattr } for comm="android:ui" path="/" dev="dm-0"
    scontext=u:r:system_app:s0 tcontext=u:object_r:rootfs:s0 tclass=dir
    avc: granted { getattr } for comm="android:ui" path="/" dev="dm-0"
    scontext=u:r:system_app:s0 tcontext=u:object_r:rootfs:s0 tclass=dir
    
    tcontext=update_engine
    avc: granted { getattr } for comm="update_engine" path="/" dev="dm-0"
    ino=2 scontext=u:r:update_engine:s0 tcontext=u:object_r:rootfs:s0
    tclass=dir
    avc: granted { getattr } for comm="update_engine" path="/fstab.foo"
    dev="dm-0" ino=25 scontext=u:r:update_engine:s0
    tcontext=u:object_r:rootfs:s0 tclass=file
    avc: granted { read open } for comm="update_engine" path="/fstab.foo"
    dev="dm-0" ino=25 scontext=u:r:update_engine:s0
    tcontext=u:object_r:rootfs:s0 tclass=file
    
    Bug: 28760354
    Test: build
    Change-Id: I6135eea1d10b903a4a7e69da468097f495484665
    a12aad45
    History
    domain_deprecated: remove rootfs access
    Jeff Vander Stoep authored
    Grant audited permissions collected in logs.
    
    tcontext=platform_app
    avc: granted { getattr } for comm=496E666C6174657254687265616420
    path="/" dev="dm-0" ino=2 scontext=u:r:platform_app:s0:c512,c768
    tcontext=u:object_r:rootfs:s0 tclass=dir
    
    tcontext=system_app
    avc: granted { getattr } for comm="android:ui" path="/" dev="dm-0"
    scontext=u:r:system_app:s0 tcontext=u:object_r:rootfs:s0 tclass=dir
    avc: granted { getattr } for comm="android:ui" path="/" dev="dm-0"
    scontext=u:r:system_app:s0 tcontext=u:object_r:rootfs:s0 tclass=dir
    
    tcontext=update_engine
    avc: granted { getattr } for comm="update_engine" path="/" dev="dm-0"
    ino=2 scontext=u:r:update_engine:s0 tcontext=u:object_r:rootfs:s0
    tclass=dir
    avc: granted { getattr } for comm="update_engine" path="/fstab.foo"
    dev="dm-0" ino=25 scontext=u:r:update_engine:s0
    tcontext=u:object_r:rootfs:s0 tclass=file
    avc: granted { read open } for comm="update_engine" path="/fstab.foo"
    dev="dm-0" ino=25 scontext=u:r:update_engine:s0
    tcontext=u:object_r:rootfs:s0 tclass=file
    
    Bug: 28760354
    Test: build
    Change-Id: I6135eea1d10b903a4a7e69da468097f495484665