Skip to content
Snippets Groups Projects
  • Nick Kralevich's avatar
    f8f937a1
    undeprecate /proc/cpuinfo, more shell permissions · f8f937a1
    Nick Kralevich authored
    Access to /proc/cpuinfo was moved to domain_deprecated in commit
    6e3506e1. Restore access to everyone.
    
    Allow the shell user to stat() /dev, and vfsstat() /proc and other
    labeled filesystems such as /system and /data.
    
    Access to /proc/cpuinfo was explicitly granted to bootanim, but is no
    longer required after moving it back to domain.te. Delete the redundant
    entry.
    
    Commit 4e2d2245 restored access to
    /sys/devices/system/cpu for all domains, but forgot to remove the
    redundant entry from bootanim.te. Cleanup the redundant entry.
    
    Addresses the following denials:
    
      avc: denied { getattr } for pid=23648 comm="bionic-unit-tes" name="/" dev="proc" ino=1 scontext=u:r:shell:s0 tcontext=u:object_r:proc:s0 tclass=filesystem permissive=0
      avc: denied { read } for name="cpuinfo" dev="proc" ino=4026533615 scontext=u:r:shell:s0 tcontext=u:object_r:proc_cpuinfo:s0 tclass=file permissive=0
      avc: denied { getattr } for pid=23713 comm="bionic-unit-tes" path="/dev" dev="tmpfs" ino=11405 scontext=u:r:shell:s0 tcontext=u:object_r:device:s0 tclass=dir permissive=0
      avc: denied { getattr } for name="/" dev="mmcblk0p30" ino=2 scontext=u:r:shell:s0 tcontext=u:object_r:labeledfs:s0 tclass=filesystem permissive=0
    
    Bug: 26295417
    Change-Id: Ia85ac91cbd43235c0f8fe0aebafffb8046cc77ec
    f8f937a1
    History
    undeprecate /proc/cpuinfo, more shell permissions
    Nick Kralevich authored
    Access to /proc/cpuinfo was moved to domain_deprecated in commit
    6e3506e1. Restore access to everyone.
    
    Allow the shell user to stat() /dev, and vfsstat() /proc and other
    labeled filesystems such as /system and /data.
    
    Access to /proc/cpuinfo was explicitly granted to bootanim, but is no
    longer required after moving it back to domain.te. Delete the redundant
    entry.
    
    Commit 4e2d2245 restored access to
    /sys/devices/system/cpu for all domains, but forgot to remove the
    redundant entry from bootanim.te. Cleanup the redundant entry.
    
    Addresses the following denials:
    
      avc: denied { getattr } for pid=23648 comm="bionic-unit-tes" name="/" dev="proc" ino=1 scontext=u:r:shell:s0 tcontext=u:object_r:proc:s0 tclass=filesystem permissive=0
      avc: denied { read } for name="cpuinfo" dev="proc" ino=4026533615 scontext=u:r:shell:s0 tcontext=u:object_r:proc_cpuinfo:s0 tclass=file permissive=0
      avc: denied { getattr } for pid=23713 comm="bionic-unit-tes" path="/dev" dev="tmpfs" ino=11405 scontext=u:r:shell:s0 tcontext=u:object_r:device:s0 tclass=dir permissive=0
      avc: denied { getattr } for name="/" dev="mmcblk0p30" ino=2 scontext=u:r:shell:s0 tcontext=u:object_r:labeledfs:s0 tclass=filesystem permissive=0
    
    Bug: 26295417
    Change-Id: Ia85ac91cbd43235c0f8fe0aebafffb8046cc77ec
domain_deprecated.te 2.96 KiB