From f1b92488f561d4fd27c6d4360f4d0ab3f3127203 Mon Sep 17 00:00:00 2001
From: Nick Kralevich <nnk@google.com>
Date: Thu, 12 Jun 2014 18:54:10 -0700
Subject: [PATCH] runas: allow pipe communication from the shell

run-as won't communicate with shell via pipes. Allow it.

  nnk@nnk:~$ adb shell "cat /dev/zero | run-as com.google.foo sh -c 'cat'"
  /system/bin/sh: cat: <stdout>: Broken pipe

  <4>[ 1485.483517] type=1400 audit(1402623577.085:25): avc: denied { read } for pid=6026 comm="run-as" path="pipe:[29823]" dev="pipefs" ino=29823 scontext=u:r:runas:s0 tcontext=u:r:shell:s0 tclass=fifo_file

read is definitely needed. Not sure about write, but adding it just
in case.

(cherry picked from commit 6c9c58884a97f36785c7778940ee303838fd2ebc)

Change-Id: Ifed6314588723063531982b45a56b902dfe32ea9
---
 runas.te | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/runas.te b/runas.te
index 8648ee711..696eff768 100644
--- a/runas.te
+++ b/runas.te
@@ -4,7 +4,8 @@ type runas_exec, exec_type, file_type;
 # ndk-gdb invokes adb shell run-as.
 domain_auto_trans(shell, runas_exec, runas)
 allow runas adbd:process sigchld;
-allow runas shell:fd  use;
+allow runas shell:fd use;
+allow runas shell:fifo_file { read write };
 allow runas devpts:chr_file { read write ioctl };
 
 # run-as reads package information.
-- 
GitLab