Skip to content
Snippets Groups Projects
  • Nick Kralevich's avatar
    e0d5c532
    exclude su from app auditallow · e0d5c532
    Nick Kralevich authored
    su is an appdomain, and as such, any auditallow statements applicable to
    appdomain also apply to su. However, su is never enforced, so generating
    SELinux denials for such domains is pointless. Exclude su from
    ion_device auditallow rules.
    
    Addresses the following auditallow spam:
    
      avc: granted { ioctl } for comm="screencap" path="/dev/ion" dev="tmpfs"
      ino=10230 ioctlcmd=4906 scontext=u:r:su:s0
      tcontext=u:object_r:ion_device:s0 tclass=chr_file
    
    Test: policy compiles
    Change-Id: I2e783624b9e53ad365669bd6f2d4db40da475a16
    e0d5c532
    History
    exclude su from app auditallow
    Nick Kralevich authored
    su is an appdomain, and as such, any auditallow statements applicable to
    appdomain also apply to su. However, su is never enforced, so generating
    SELinux denials for such domains is pointless. Exclude su from
    ion_device auditallow rules.
    
    Addresses the following auditallow spam:
    
      avc: granted { ioctl } for comm="screencap" path="/dev/ion" dev="tmpfs"
      ino=10230 ioctlcmd=4906 scontext=u:r:su:s0
      tcontext=u:object_r:ion_device:s0 tclass=chr_file
    
    Test: policy compiles
    Change-Id: I2e783624b9e53ad365669bd6f2d4db40da475a16