diff --git a/domain.te b/domain.te index 023eac303feef62816f10641d9e737b8c4c4c331..3c7d596f88ff80a6e0b77303782663311ada9c6f 100644 --- a/domain.te +++ b/domain.te @@ -572,25 +572,6 @@ neverallow * domain:file { execute execute_no_trans entrypoint }; # TODO: fix system_server and dumpstate neverallow { domain -init -system_server -dumpstate } debugfs:file no_rw_file_perms; -neverallow { - domain - -init - -recovery - -sdcardd - -vold -} fuse_device:chr_file open; -neverallow { - domain - -dumpstate - -init - -priv_app - -recovery - -sdcardd - -system_server - -ueventd - -vold -} fuse_device:chr_file *; - # Profiles contain untrusted data and profman parses that. We should only run # in from installd forked processes. neverallow {