Skip to content
Snippets Groups Projects
Commit 782e084d authored by Stephen Smalley's avatar Stephen Smalley
Browse files

Allow system_server to read tombstones.


Address denials such as:
 avc:  denied  { read } for  name="tombstones" dev="dm-0" ino=765537 scontext=u:r:system_server:s0 tcontext=u:object_r:tombstone_data_file:s0 tclass=dir
 avc:  denied  { open } for  name="tombstones" dev="dm-0" ino=765537 scontext=u:r:system_server:s0 tcontext=u:object_r:tombstone_data_file:s0 tclass=dir
 avc:  denied  { getattr } for  path="/data/tombstones/tombstone_00" dev="dm-0" ino=765538 scontext=u:r:system_server:s0 tcontext=u:object_r:tombstone_data_file:s0 tclass=file
 avc:  denied  { read } for  name="tombstone_00" dev="dm-0" ino=765538 scontext=u:r:system_server:s0 tcontext=u:object_r:tombstone_data_file:s0 tclass=file
 avc:  denied  { open } for  name="tombstone_00" dev="dm-0" ino=765538 scontext=u:r:system_server:s0 tcontext=u:object_r:tombstone_data_file:s0 tclass=file

Change-Id: Iae5a10bed9483589660b84a88b6b9f8f8e9a8f5c
Signed-off-by: default avatarStephen Smalley <sds@tycho.nsa.gov>
parent 45206a38
No related branches found
No related tags found
No related merge requests found
...@@ -211,6 +211,10 @@ allow system_server radio_data_file:file create_file_perms; ...@@ -211,6 +211,10 @@ allow system_server radio_data_file:file create_file_perms;
allow system_server systemkeys_data_file:dir create_dir_perms; allow system_server systemkeys_data_file:dir create_dir_perms;
allow system_server systemkeys_data_file:file create_file_perms; allow system_server systemkeys_data_file:file create_file_perms;
# Access /data/tombstones.
allow system_server tombstone_data_file:dir r_dir_perms;
allow system_server tombstone_data_file:file r_file_perms;
# Manage /data/misc/vpn. # Manage /data/misc/vpn.
allow system_server vpn_data_file:dir create_dir_perms; allow system_server vpn_data_file:dir create_dir_perms;
allow system_server vpn_data_file:file create_file_perms; allow system_server vpn_data_file:file create_file_perms;
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment