Skip to content
Snippets Groups Projects
Commit 270be6e8 authored by Nick Kralevich's avatar Nick Kralevich
Browse files

dex2oat: fix forward-locked upgrades with unlabeled asecs

dex2oat fails when upgrading unlabeled asec containers.

Steps to reproduce:

1) Install a forward locked app on Android 4.1
  adb install -l foo.apk
2) Upgrade to tip-of-tree

Addresses the following denial:

  <4>[  379.886665] type=1400 audit(1405549869.210:4): avc: denied { read } for pid=2389 comm="dex2oat" path="/mnt/asec/jackpal.androidterm-1/pkg.apk" dev=dm-0 ino=12 scontext=u:r:dex2oat:s0 tcontext=u:object_r:unlabeled:s0 tclass=file

Change-Id: I58dc6ebe61a5b5840434077a55f1afbeed602137
parent 6a1405d7
No related branches found
No related tags found
No related merge requests found
...@@ -6,4 +6,7 @@ allow dex2oat dalvikcache_data_file:file write; ...@@ -6,4 +6,7 @@ allow dex2oat dalvikcache_data_file:file write;
allow dex2oat installd:fd use; allow dex2oat installd:fd use;
# Read already open asec_apk_file file descriptors passed by installd. # Read already open asec_apk_file file descriptors passed by installd.
# Also allow reading unlabeled files, to allow for upgrading forward
# locked APKs.
allow dex2oat asec_apk_file:file read; allow dex2oat asec_apk_file:file read;
allow dex2oat unlabeled:file read;
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment