Skip to content
Snippets Groups Projects
Commit 9a76c280 authored by Treehugger Robot's avatar Treehugger Robot Committed by Gerrit Code Review
Browse files

Merge "Suppress harmless denials for file creation in cgroupfs."

parents 2c36eb6d 832a7042
No related branches found
No related tags found
No related merge requests found
......@@ -25,3 +25,8 @@ userdebug_or_eng(`
# Sometimes we have to write to non-existent files to avoid conditional
# init behavior. See b/35303861 for an example.
dontaudit init sysfs:dir write;
# Suppress false positives when using O_CREAT
# to open a file that already exists.
# There's a neverallow rule for this in domain.te
dontaudit init cgroup:file create;
......@@ -134,3 +134,8 @@ neverallow zygote {
# Do not allow access to Bluetooth-related system properties and files
neverallow zygote bluetooth_prop:file create_file_perms;
# Suppress false positives when using O_CREAT
# to open a file that already exists.
# There's a neverallow rule for this in domain.te
dontaudit zygote cgroup:file create;
......@@ -1331,6 +1331,13 @@ neverallow domain {
sysfs_type
}:dir { add_name create link remove_name rename reparent rmdir write };
# cgroupfs directories can be created, but not files within them
# TODO(b/74182216): Remove the installd allow when we're sure it's not used
neverallow {
domain
-installd
} cgroup:file create;
dontaudit domain proc_type:dir write;
dontaudit domain sysfs_type:dir write;
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment