Skip to content
Snippets Groups Projects
Commit 0d22c6ce authored by Mark Salyzyn's avatar Mark Salyzyn
Browse files

logd: logpersistd

- Enable logpersistd to write to /data/misc/logd
- Enable logpersistd to read from pstore to help complete any content
  lost by reboot disruption
- Enable shell readonly ability logpersistd files in /data/misc/logd
- Enable logcat -f when placed into logd context to act as a
  logpersistd (nee logcatd) agent, restrict access to run only in
  userdebug or eng

Bug: 19608716
Change-Id: I3209582bc796a1093c325c90068a48bf268e5ab5
parent bf0c34d5
No related branches found
No related tags found
No related merge requests found
...@@ -165,6 +165,7 @@ type logdr_socket, file_type, mlstrustedobject; ...@@ -165,6 +165,7 @@ type logdr_socket, file_type, mlstrustedobject;
type logdw_socket, file_type, mlstrustedobject; type logdw_socket, file_type, mlstrustedobject;
type mdns_socket, file_type; type mdns_socket, file_type;
type mdnsd_socket, file_type, mlstrustedobject; type mdnsd_socket, file_type, mlstrustedobject;
type misc_logd_file, file_type;
type mtpd_socket, file_type; type mtpd_socket, file_type;
type netd_socket, file_type; type netd_socket, file_type;
type property_socket, file_type; type property_socket, file_type;
......
...@@ -236,6 +236,7 @@ ...@@ -236,6 +236,7 @@
/data/misc/gatekeeper(/.*)? u:object_r:gatekeeper_data_file:s0 /data/misc/gatekeeper(/.*)? u:object_r:gatekeeper_data_file:s0
/data/misc/keychain(/.*)? u:object_r:keychain_data_file:s0 /data/misc/keychain(/.*)? u:object_r:keychain_data_file:s0
/data/misc/keystore(/.*)? u:object_r:keystore_data_file:s0 /data/misc/keystore(/.*)? u:object_r:keystore_data_file:s0
/data/misc/logd(/.*)? u:object_r:misc_logd_file:s0
/data/misc/media(/.*)? u:object_r:media_data_file:s0 /data/misc/media(/.*)? u:object_r:media_data_file:s0
/data/misc/net(/.*)? u:object_r:net_data_file:s0 /data/misc/net(/.*)? u:object_r:net_data_file:s0
/data/misc/shared_relro(/.*)? u:object_r:shared_relro_file:s0 /data/misc/shared_relro(/.*)? u:object_r:shared_relro_file:s0
......
...@@ -161,6 +161,10 @@ recovery_only(` ...@@ -161,6 +161,10 @@ recovery_only(`
domain_trans(init, shell_exec, shell) domain_trans(init, shell_exec, shell)
domain_trans(init, init_exec, ueventd) domain_trans(init, init_exec, ueventd)
domain_trans(init, init_exec, watchdogd) domain_trans(init, init_exec, watchdogd)
# case where logpersistd is actually logcat -f in logd context (nee: logcatd)
userdebug_or_eng(`
domain_auto_trans(init, logcat_exec, logd)
')
# Support "adb shell stop" # Support "adb shell stop"
allow init self:capability kill; allow init self:capability kill;
......
...@@ -10,6 +10,10 @@ allow logd self:netlink_audit_socket { create_socket_perms nlmsg_write }; ...@@ -10,6 +10,10 @@ allow logd self:netlink_audit_socket { create_socket_perms nlmsg_write };
allow logd kernel:system syslog_read; allow logd kernel:system syslog_read;
allow logd kmsg_device:chr_file w_file_perms; allow logd kmsg_device:chr_file w_file_perms;
allow logd system_data_file:file r_file_perms; allow logd system_data_file:file r_file_perms;
allow logd misc_logd_file:file create_file_perms;
allow logd misc_logd_file:dir rw_dir_perms;
allow logd pstorefs:dir search;
allow logd pstorefs:file r_file_perms;
r_dir_file(logd, domain) r_dir_file(logd, domain)
...@@ -17,6 +21,11 @@ allow logd kernel:system syslog_mod; ...@@ -17,6 +21,11 @@ allow logd kernel:system syslog_mod;
control_logd(logd) control_logd(logd)
# case where logpersistd is actually logcat -f in logd context (nee: logcatd)
userdebug_or_eng(`
unix_socket_connect(logd, logdr, logd)
')
### ###
### Neverallow rules ### Neverallow rules
### ###
......
...@@ -15,6 +15,9 @@ control_logd(shell) ...@@ -15,6 +15,9 @@ control_logd(shell)
# logcat -L (directly, or via dumpstate) # logcat -L (directly, or via dumpstate)
allow shell pstorefs:dir search; allow shell pstorefs:dir search;
allow shell pstorefs:file r_file_perms; allow shell pstorefs:file r_file_perms;
# logpersistd (nee logcatd) files
allow shell misc_logd_file:dir r_dir_perms;
allow shell misc_logd_file:file r_file_perms;
# read files in /data/anr # read files in /data/anr
allow shell anr_data_file:dir r_dir_perms; allow shell anr_data_file:dir r_dir_perms;
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment