Skip to content
Snippets Groups Projects
Commit daac339f authored by Treehugger Robot's avatar Treehugger Robot Committed by Gerrit Code Review
Browse files

Merge "Don't allow dexoptanalyzer to open app_data_files"

parents 8228c1dc b8a42499
No related branches found
No related tags found
No related merge requests found
......@@ -20,7 +20,7 @@ allow dexoptanalyzer installd:fd use;
# Allow reading secondary dex files that were reported by the app to the
# package manager.
allow dexoptanalyzer app_data_file:dir { getattr search };
allow dexoptanalyzer app_data_file:file r_file_perms;
allow dexoptanalyzer app_data_file:file { getattr read };
# dexoptanalyzer calls access(2) with W_OK flag on app data. We can use the
# "dontaudit...audit_access" policy line to suppress the audit access without
# suppressing denial on actual access.
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment