Skip to content
Snippets Groups Projects
Commit 3ade7cef authored by Jeff Sharkey's avatar Jeff Sharkey
Browse files

Allow 'vdc' to be invoked with logwrapper.

Currently vdc emits logs to stderr, which makes sense for command
line invocations, but when exec'ed they're silently dropped unless
the caller uses logwrapper.

avc: denied { read write } for path="/dev/pts/2" dev="devpts" ino=5 scontext=u:r:vdc:s0 tcontext=u:object_r:devpts:s0 tclass=chr_file permissive=0

Bug: 25796509
Change-Id: Ib92e0a7f580b1934a9853a83684f95b24bdc355c
parent 613f451e
Branches
Tags
No related merge requests found
...@@ -21,3 +21,6 @@ allow vdc shell_data_file:file { write getattr }; ...@@ -21,3 +21,6 @@ allow vdc shell_data_file:file { write getattr };
# Why? # Why?
allow vdc dumpstate:unix_dgram_socket { read write }; allow vdc dumpstate:unix_dgram_socket { read write };
# vdc can be invoked with logwrapper, so let it write to pty
allow vdc devpts:chr_file rw_file_perms;
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment