Skip to content
Snippets Groups Projects
Commit ac457004 authored by Treehugger Robot's avatar Treehugger Robot Committed by Gerrit Code Review
Browse files

Merge "dumpstate: remove JIT and /data execute"

parents 36c7f741 eef72d34
Branches objtool
No related tags found
No related merge requests found
...@@ -8,9 +8,6 @@ domain_auto_trans(dumpstate, vdc_exec, vdc) ...@@ -8,9 +8,6 @@ domain_auto_trans(dumpstate, vdc_exec, vdc)
# Acquire advisory lock on /system/etc/xtables.lock from ip[6]tables # Acquire advisory lock on /system/etc/xtables.lock from ip[6]tables
allow dumpstate system_file:file lock; allow dumpstate system_file:file lock;
# TODO: deal with tmpfs_domain pub/priv split properly
allow dumpstate dumpstate_tmpfs:file execute;
# systrace support - allow atrace to run # systrace support - allow atrace to run
allow dumpstate debugfs_tracing:dir r_dir_perms; allow dumpstate debugfs_tracing:dir r_dir_perms;
allow dumpstate debugfs_tracing:file rw_file_perms; allow dumpstate debugfs_tracing:file rw_file_perms;
......
...@@ -428,7 +428,6 @@ neverallow { ...@@ -428,7 +428,6 @@ neverallow {
domain domain
-appdomain -appdomain
with_asan(`-asan_extract') with_asan(`-asan_extract')
-dumpstate
-shell -shell
userdebug_or_eng(`-su') userdebug_or_eng(`-su')
-webview_zygote -webview_zygote
......
...@@ -137,13 +137,6 @@ allow dumpstate shell_exec:file rx_file_perms; ...@@ -137,13 +137,6 @@ allow dumpstate shell_exec:file rx_file_perms;
# For running am and similar framework commands. # For running am and similar framework commands.
# Run /system/bin/app_process. # Run /system/bin/app_process.
allow dumpstate zygote_exec:file rx_file_perms; allow dumpstate zygote_exec:file rx_file_perms;
# Dalvik Compiler JIT.
allow dumpstate ashmem_device:chr_file execute;
allow dumpstate self:process execmem;
# For art.
allow dumpstate dalvikcache_data_file:dir { search getattr };
allow dumpstate dalvikcache_data_file:file { r_file_perms execute };
allow dumpstate dalvikcache_data_file:lnk_file r_file_perms;
# For Bluetooth # For Bluetooth
allow dumpstate bluetooth_data_file:dir search; allow dumpstate bluetooth_data_file:dir search;
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment