diff --git a/vold.te b/vold.te index af050c8805f93f133d5344111f262b02e86e4bd8..35134106d8282becc6bca22a8b68321324f237ef 100644 --- a/vold.te +++ b/vold.te @@ -156,6 +156,9 @@ allow vold vold_data_file:file create_file_perms; allow vold init:key { write search setattr }; allow vold vold:key { write search setattr }; +# vold temporarily changes its priority when running benchmarks +allow vold self:capability sys_nice; + neverallow { domain -vold } vold_data_file:dir ~{ open create read getattr setattr search relabelto ioctl }; neverallow { domain -vold } vold_data_file:notdevfile_class_set ~{ relabelto getattr }; neverallow { domain -vold -init } vold_data_file:dir *;