Skip to content
Snippets Groups Projects
Commit cfd9b6ba authored by Stephen Smalley's avatar Stephen Smalley
Browse files

Allow apps to execute the shell or system commands unconditionally.


Change-Id: I54af993bd478d6b8d0462d43950bb1a991131c82
Signed-off-by: default avatarStephen Smalley <sds@tycho.nsa.gov>
parent ab0cd211
No related branches found
No related tags found
No related merge requests found
...@@ -132,6 +132,10 @@ allow appdomain platform_app_data_file:file { getattr read write }; ...@@ -132,6 +132,10 @@ allow appdomain platform_app_data_file:file { getattr read write };
allow appdomain system_data_file:dir r_dir_perms; allow appdomain system_data_file:dir r_dir_perms;
allow appdomain system_data_file:file { execute open }; allow appdomain system_data_file:file { execute open };
# Execute the shell or other system executables.
allow appdomain shell_exec:file rx_file_perms;
allow appdomain system_file:file rx_file_perms;
# Read/write wallpaper file (opened by system). # Read/write wallpaper file (opened by system).
allow appdomain wallpaper_file:file { read write }; allow appdomain wallpaper_file:file { read write };
......
...@@ -23,10 +23,6 @@ allow appdomain file_type:dir_file_class_set getattr; ...@@ -23,10 +23,6 @@ allow appdomain file_type:dir_file_class_set getattr;
allow appdomain dev_type:dir_file_class_set getattr; allow appdomain dev_type:dir_file_class_set getattr;
allow appdomain fs_type:dir_file_class_set getattr; allow appdomain fs_type:dir_file_class_set getattr;
# Execute the shell or other system executables.
allow appdomain shell_exec:file rx_file_perms;
allow appdomain system_file:file rx_file_perms;
# Accesses to apk_tmp_file and shell_data_file # Accesses to apk_tmp_file and shell_data_file
allow appdomain apk_tmp_file:file rw_file_perms; allow appdomain apk_tmp_file:file rw_file_perms;
allow appdomain shell_data_file:file r_file_perms; allow appdomain shell_data_file:file r_file_perms;
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment