Skip to content
Snippets Groups Projects
Commit c1e48835 authored by Daniel Cashman's avatar Daniel Cashman Committed by Gerrit Code Review
Browse files

Merge "Remove appdomain sysfs auditallow."

parents e931bdd6 0b80f4dc
No related branches found
No related tags found
No related merge requests found
...@@ -226,10 +226,6 @@ allow appdomain runas_exec:file getattr; ...@@ -226,10 +226,6 @@ allow appdomain runas_exec:file getattr;
selinux_check_access(appdomain) selinux_check_access(appdomain)
selinux_check_context(appdomain) selinux_check_context(appdomain)
# appdomain should not be accessing information on /sys
auditallow { appdomain userdebug_or_eng(`-su') } sysfs:dir { open getattr read ioctl };
auditallow { appdomain userdebug_or_eng(`-su') } sysfs:file r_file_perms;
# Apps receive an open tun fd from the framework for # Apps receive an open tun fd from the framework for
# device traffic. Do not allow untrusted app to directly open tun_device # device traffic. Do not allow untrusted app to directly open tun_device
allow { appdomain -isolated_app } tun_device:chr_file { read write getattr ioctl append }; allow { appdomain -isolated_app } tun_device:chr_file { read write getattr ioctl append };
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment