Skip to content
Snippets Groups Projects
  • Nick Kralevich's avatar
    0af2aa0b
    su.te: drop domain_deprecated and app auditallow rules. · 0af2aa0b
    Nick Kralevich authored
    su is in permissive all the time. We don't want SELinux log
    spam from this domain.
    
    Addresses the following logspam:
    
      avc: granted { getattr } for comm="lsof" path="/sys/devices/virtual/graphics/fb0/vsync_event" dev="sysfs" ino=10815 scontext=u:r:su:s0 tcontext=u:object_r:sysfs:s0 tclass=file
      avc: granted { getattr } for comm="lsof" path="/sys/devices/virtual/thermal/thermal_zone2/temp" dev="sysfs" ino=15368 scontext=u:r:su:s0 tcontext=u:object_r:sysfs:s0 tclass=file
      avc: granted { read } for comm="sh" name="emmc_therm" dev="sysfs" ino=17583 scontext=u:r:su:s0 tcontext=u:object_r:sysfs:s0 tclass=file
    
    Change-Id: I8e17d3814e41b497b25ce00cd72698f0d22b3ab0
    0af2aa0b
    History
    su.te: drop domain_deprecated and app auditallow rules.
    Nick Kralevich authored
    su is in permissive all the time. We don't want SELinux log
    spam from this domain.
    
    Addresses the following logspam:
    
      avc: granted { getattr } for comm="lsof" path="/sys/devices/virtual/graphics/fb0/vsync_event" dev="sysfs" ino=10815 scontext=u:r:su:s0 tcontext=u:object_r:sysfs:s0 tclass=file
      avc: granted { getattr } for comm="lsof" path="/sys/devices/virtual/thermal/thermal_zone2/temp" dev="sysfs" ino=15368 scontext=u:r:su:s0 tcontext=u:object_r:sysfs:s0 tclass=file
      avc: granted { read } for comm="sh" name="emmc_therm" dev="sysfs" ino=17583 scontext=u:r:su:s0 tcontext=u:object_r:sysfs:s0 tclass=file
    
    Change-Id: I8e17d3814e41b497b25ce00cd72698f0d22b3ab0