Skip to content
Snippets Groups Projects
Commit 106050f8 authored by Nick Kralevich's avatar Nick Kralevich Committed by Android Git Automerger
Browse files

am 0d3f7ddc: remove appdomain\'s ability to examine all of /proc

* commit '0d3f7ddc':
  remove appdomain's ability to examine all of /proc
parents eb8e3d60 0d3f7ddc
No related branches found
No related tags found
No related merge requests found
......@@ -152,14 +152,6 @@ allow appdomain resourcecache_data_file:dir r_dir_perms;
### CTS-specific rules
###
# For cts/tools/device-setup/TestDeviceSetup/src/android/tests/getinfo/RootProcessScanner.java.
# Reads /proc/pid/status and statm entries to check that
# no unexpected root processes are running.
# Also for cts/tests/tests/security/src/android/security/cts/VoldExploitTest.java
# Reads /proc/pid/cmdline of vold.
allow appdomain domain:dir { open read search getattr };
allow appdomain domain:{ file lnk_file } { open read getattr };
# For cts/tests/tests/permission/src/android/permission/cts/FileSystemPermissionTest.java.
# testRunAsHasCorrectCapabilities
allow appdomain runas_exec:file getattr;
......
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please to comment