Skip to content
Snippets Groups Projects
Commit 466fd7fa authored by Yabin Cui's avatar Yabin Cui Committed by android-build-merger
Browse files

Merge "Allow init and vold writing misc block device." into nyc-dev

am: 541e9d50

* commit '541e9d50':
  Allow init and vold writing misc block device.

Change-Id: Ifcf032d5afd8b576246ba5c8e00c039bbf6e8059
parents 35d91f67 541e9d50
Branches
Tags
No related merge requests found
......@@ -329,6 +329,9 @@ allow init unencrypted_data_file:dir create_dir_perms;
unix_socket_connect(init, vold, vold)
# Raw writes to misc block device
allow init misc_block_device:blk_file w_file_perms;
###
### neverallow rules
###
......
......@@ -188,6 +188,9 @@ allow vold toolbox_exec:file rx_file_perms;
allow vold user_profile_data_file:dir create_dir_perms;
allow vold user_profile_foreign_dex_data_file:dir { getattr setattr };
# Raw writes to misc block device
allow vold misc_block_device:blk_file w_file_perms;
neverallow { domain -vold } vold_data_file:dir ~{ open create read getattr setattr search relabelto ioctl };
neverallow { domain -vold } vold_data_file:notdevfile_class_set ~{ relabelto getattr };
neverallow { domain -vold -init } vold_data_file:dir *;
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment