Skip to content
Snippets Groups Projects
  • Geremy Condra's avatar
    3bb1ccc2
    Fix long-tail denials in enforcing domains. · 3bb1ccc2
    Geremy Condra authored
    The specific denials we see are:
    
    denied  { getattr } for  pid=169 comm=""installd"" path=""/data/data/com.android.providers.downloads/cache/downloadfile.jpeg"" dev=""mmcblk0p23"" ino=602861 scontext=u:r:installd:s0 tcontext=u:object_r:download_file:s0 tclass=file
    denied  { fsetid } for  pid=598 comm=""netd"" capability=4  scontext=u:r:netd:s0 tcontext=u:r:netd:s0 tclass=capability
    denied  { read } for  pid=209 comm=""installd"" name=""cache"" dev=""mmcblk0p28"" ino=81694 scontext=u:r:installd:s0 tcontext=u:object_r:download_file:s0 tclass=dir
    
    Bug: 10786017
    Change-Id: Ia5d0b6337f3de6a168ac0d5a77df2a1ac419ec29
    3bb1ccc2
    History
    Fix long-tail denials in enforcing domains.
    Geremy Condra authored
    The specific denials we see are:
    
    denied  { getattr } for  pid=169 comm=""installd"" path=""/data/data/com.android.providers.downloads/cache/downloadfile.jpeg"" dev=""mmcblk0p23"" ino=602861 scontext=u:r:installd:s0 tcontext=u:object_r:download_file:s0 tclass=file
    denied  { fsetid } for  pid=598 comm=""netd"" capability=4  scontext=u:r:netd:s0 tcontext=u:r:netd:s0 tclass=capability
    denied  { read } for  pid=209 comm=""installd"" name=""cache"" dev=""mmcblk0p28"" ino=81694 scontext=u:r:installd:s0 tcontext=u:object_r:download_file:s0 tclass=dir
    
    Bug: 10786017
    Change-Id: Ia5d0b6337f3de6a168ac0d5a77df2a1ac419ec29