Skip to content
Snippets Groups Projects
Commit 178be151 authored by Chenbo Feng's avatar Chenbo Feng Committed by android-build-merger
Browse files

Merge "Revert "Remove app access to qtaguid ctrl/stats file""

am: 2904db67

Change-Id: I1905f28cdcfee2e96d69ffde8adfe77865a882d2
parents e8913ef5 2904db67
Branches
Tags
No related merge requests found
...@@ -169,7 +169,15 @@ userdebug_or_eng(` ...@@ -169,7 +169,15 @@ userdebug_or_eng(`
allow appdomain heapdump_data_file:file append; allow appdomain heapdump_data_file:file append;
') ')
# Write to /proc/net/xt_qtaguid/ctrl file.
allow appdomain qtaguid_proc:file rw_file_perms;
r_dir_file({ appdomain -ephemeral_app -isolated_app }, proc_net) r_dir_file({ appdomain -ephemeral_app -isolated_app }, proc_net)
# read /proc/net/xt_qtguid/*stat* to per-app network data usage.
# Exclude isolated app which may not use network sockets.
r_dir_file({ appdomain -isolated_app }, proc_qtaguid_stat)
# Everybody can read the xt_qtaguid resource tracking misc dev.
# So allow all apps to read from /dev/xt_qtaguid.
allow { appdomain -isolated_app } qtaguid_device:chr_file r_file_perms;
# Grant GPU access to all processes started by Zygote. # Grant GPU access to all processes started by Zygote.
# They need that to render the standard UI. # They need that to render the standard UI.
...@@ -542,8 +550,3 @@ neverallow appdomain proc_uid_concurrent_policy_time:file *; ...@@ -542,8 +550,3 @@ neverallow appdomain proc_uid_concurrent_policy_time:file *;
# Apps cannot access proc_uid_cpupower # Apps cannot access proc_uid_cpupower
neverallow appdomain proc_uid_cpupower:file *; neverallow appdomain proc_uid_cpupower:file *;
# Apps cannot access proc/net/xt_qtaguid/ files anymore since P.
neverallow { appdomain -shell } qtaguid_proc:file rw_file_perms;
neverallow { appdomain -shell } proc_qtaguid_stat:{ file lnk_file } r_file_perms;
neverallow { appdomain -shell } qtaguid_device:chr_file r_file_perms;
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment