diff --git a/private/system_server.te b/private/system_server.te index 920658fe20ebe7091c1ecc4f8094bc40b56e7d89..14f02eb941faeec9949d1132aa5e76b6aeafed32 100644 --- a/private/system_server.te +++ b/private/system_server.te @@ -789,8 +789,7 @@ neverallow system_server { domain -system_server }:process ptrace; # CAP_SYS_RESOURCE was traditionally needed for sensitive /proc/PID # file read access. However, that is now unnecessary (b/34951864) -# This neverallow can be removed after b/34951864 is fixed. -neverallow system_server system_server:capability sys_resource; +neverallow system_server system_server:global_capability_class_set sys_resource; # TODO(b/67468181): Remove following lines upon resolution of this bug dontaudit system_server statscompanion_service:service_manager { add find };