Skip to content
Snippets Groups Projects
Commit edbe1a98 authored by Daniel Cashman's avatar Daniel Cashman Committed by Android (Google) Code Review
Browse files

Merge "Label /proc/meminfo." into nyc-dev

parents 84cc52c5 971aeeda
No related branches found
No related tags found
No related merge requests found
...@@ -57,6 +57,7 @@ r_dir_file(domain_deprecated, proc) ...@@ -57,6 +57,7 @@ r_dir_file(domain_deprecated, proc)
r_dir_file(domain_deprecated, sysfs) r_dir_file(domain_deprecated, sysfs)
r_dir_file(domain_deprecated, inotify) r_dir_file(domain_deprecated, inotify)
r_dir_file(domain_deprecated, cgroup) r_dir_file(domain_deprecated, cgroup)
r_dir_file(domain_deprecated, proc_meminfo)
r_dir_file(domain_deprecated, proc_net) r_dir_file(domain_deprecated, proc_net)
# Get SELinux enforcing status. # Get SELinux enforcing status.
......
...@@ -14,6 +14,7 @@ type qtaguid_proc, fs_type, mlstrustedobject; ...@@ -14,6 +14,7 @@ type qtaguid_proc, fs_type, mlstrustedobject;
type proc_bluetooth_writable, fs_type; type proc_bluetooth_writable, fs_type;
type proc_cpuinfo, fs_type; type proc_cpuinfo, fs_type;
type proc_iomem, fs_type; type proc_iomem, fs_type;
type proc_meminfo, fs_type;
type proc_net, fs_type; type proc_net, fs_type;
type proc_sysrq, fs_type; type proc_sysrq, fs_type;
type proc_uid_cputime_showstat, fs_type; type proc_uid_cputime_showstat, fs_type;
......
...@@ -3,6 +3,7 @@ genfscon rootfs / u:object_r:rootfs:s0 ...@@ -3,6 +3,7 @@ genfscon rootfs / u:object_r:rootfs:s0
# proc labeling can be further refined (longest matching prefix). # proc labeling can be further refined (longest matching prefix).
genfscon proc / u:object_r:proc:s0 genfscon proc / u:object_r:proc:s0
genfscon proc /iomem u:object_r:proc_iomem:s0 genfscon proc /iomem u:object_r:proc_iomem:s0
genfscon proc /meminfo u:object_r:proc_meminfo:s0
genfscon proc /net u:object_r:proc_net:s0 genfscon proc /net u:object_r:proc_net:s0
genfscon proc /net/xt_qtaguid/ctrl u:object_r:qtaguid_proc:s0 genfscon proc /net/xt_qtaguid/ctrl u:object_r:qtaguid_proc:s0
genfscon proc /cpuinfo u:object_r:proc_cpuinfo:s0 genfscon proc /cpuinfo u:object_r:proc_cpuinfo:s0
......
...@@ -94,10 +94,11 @@ allow untrusted_app self:process ptrace; ...@@ -94,10 +94,11 @@ allow untrusted_app self:process ptrace;
# for files. Suppress the denials when they occur. # for files. Suppress the denials when they occur.
dontaudit untrusted_app exec_type:file getattr; dontaudit untrusted_app exec_type:file getattr;
# TODO: access of /proc/meminfo, give specific label or switch to # TODO: switch to meminfo service
# using meminfo service allow untrusted_app proc_meminfo:file r_file_perms;
allow untrusted_app proc:file r_file_perms;
# https://code.google.com/p/chromium/issues/detail?id=586021 # https://code.google.com/p/chromium/issues/detail?id=586021
allow untrusted_app proc:file r_file_perms;
auditallow untrusted_app proc:file r_file_perms; auditallow untrusted_app proc:file r_file_perms;
# access /proc/net/xt_qtguid/stats # access /proc/net/xt_qtguid/stats
r_dir_file(untrusted_app, proc_net) r_dir_file(untrusted_app, proc_net)
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment