diff --git a/private/init.te b/private/init.te index d495d5473583f56dada88cd2e4eecc4caed2b5de..8a6dcea77a510447c8edb9a70b03a5fa444f8307 100644 --- a/private/init.te +++ b/private/init.te @@ -17,3 +17,8 @@ domain_trans(init, init_exec, watchdogd) userdebug_or_eng(` domain_auto_trans(init, logcat_exec, logpersist) ') + +# Creating files on sysfs is impossible so this isn't a threat +# Sometimes we have to write to non-existent files to avoid conditional +# init behavior. See b/35303861 for an example. +dontaudit init sysfs:dir write;