From 0a5f561c673a6a781bc2f11ac60d6613c648770c Mon Sep 17 00:00:00 2001 From: Nick Kralevich <nnk@google.com> Date: Thu, 27 Feb 2014 17:24:43 -0800 Subject: [PATCH] uncrypt: allow /dev/block directory access. Uncrypt needs search in /dev/block to open block devices. Allow it. Addresses the following denial: [11105.601711] type=1400 audit(1393550350.528:30): avc: denied { search } for pid=14597 comm="uncrypt" name="block" dev="tmpfs" ino=7200 scontext=u:r:uncrypt:s0 tcontext=u:object_r:block_device:s0 tclass=dir Change-Id: I4592784135a04ff5bff2715e1250661744f12aa1 --- uncrypt.te | 1 + 1 file changed, 1 insertion(+) diff --git a/uncrypt.te b/uncrypt.te index f62fbbfd1..265a8b1a6 100644 --- a/uncrypt.te +++ b/uncrypt.te @@ -27,3 +27,4 @@ allow uncrypt powerctl_prop:property_service set; # Raw writes to block device allow uncrypt self:capability sys_rawio; allow uncrypt block_device:blk_file w_file_perms; +allow uncrypt block_device:dir r_dir_perms; -- GitLab