Skip to content
Snippets Groups Projects
Commit c24d90cb authored by Nick Kralevich's avatar Nick Kralevich
Browse files

dumpstate: allow df on /storage/emulated

dumpstate runs "df" on all mounted filesystems. Allow dumpstate
to access /storage/emulated so df works.

Addresses the following denial:

  avc: denied { search } for pid=4505 comm="df" name="/" dev="tmpfs" ino=6207 scontext=u:r:dumpstate:s0 tcontext=u:object_r:storage_file:s0 tclass=dir

Change-Id: I99dac8321b19952e37c0dd9d61a680a27beb1ae8
parent 4cdea7fc
No related branches found
No related tags found
No related merge requests found
......@@ -63,6 +63,8 @@ allow dumpstate sysfs:file w_file_perms;
# Other random bits of data we want to collect
allow dumpstate qtaguid_proc:file r_file_perms;
allow dumpstate debugfs:file r_file_perms;
# df for /storage/emulated needs search
allow dumpstate storage_file:dir search;
# Allow dumpstate to make binder calls to any binder service
binder_call(dumpstate, binderservicedomain)
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment