Skip to content
Snippets Groups Projects
Commit feabf294 authored by Tri Vo's avatar Tri Vo Committed by android-build-merger
Browse files

Merge "shell: neverallow access to 'proc' label." am: 6faa3a1a

am: 51251212

Change-Id: Ie3194b1314cef76240ff518ac2b86e094b9baa81
parents 997fcf16 51251212
No related branches found
No related tags found
No related merge requests found
......@@ -27,7 +27,6 @@ full_treble_only(`
-dumpstate
-platform_app
-priv_app
-shell
-system_app
-vold
-vendor_init
......
......@@ -107,16 +107,21 @@ hwbinder_use(shell)
allow shell hwservicemanager:hwservice_manager list;
# allow shell to look through /proc/ for lsmod, ps, top, netstat.
r_dir_file(shell, proc)
r_dir_file(shell, proc_net)
allow shell proc_filesystems:file r_file_perms;
allow shell proc_interrupts:file r_file_perms;
allow shell proc_meminfo:file r_file_perms;
allow shell proc_modules:file r_file_perms;
allow shell proc_stat:file r_file_perms;
allow shell proc_timer:file r_file_perms;
allow shell proc_version:file r_file_perms;
allow shell proc_zoneinfo:file r_file_perms;
allow shell {
proc_asound
proc_filesystems
proc_interrupts
proc_meminfo
proc_modules
proc_stat
proc_timer
proc_uptime
proc_version
proc_zoneinfo
}:file r_file_perms;
r_dir_file(shell, cgroup)
allow shell domain:dir { search open read getattr };
allow shell domain:{ file lnk_file } { open read getattr };
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment