Skip to content
Snippets Groups Projects
Commit ff6715f3 authored by Nick Kralevich's avatar Nick Kralevich Committed by android-build-merger
Browse files

profman/debuggerd: allow libart_file:file r_file_perms am: 364fd197

am: d62abbee

Change-Id: Ib9b65a933da450b4baf70a4e26c15e177ba04d16
parents abbc718f d62abbee
Branches
Tags
No related merge requests found
......@@ -23,7 +23,7 @@ allow debuggerd tombstone_data_file:file create_file_perms;
allow debuggerd shared_relro_file:dir r_dir_perms;
allow debuggerd shared_relro_file:file r_file_perms;
allow debuggerd domain:process { sigstop sigkill signal };
allow debuggerd exec_type:file r_file_perms;
allow debuggerd { exec_type libart_file }:file r_file_perms;
# Access app library
allow debuggerd system_data_file:file open;
# Allow debuggerd to redirect a dump_backtrace request to itself.
......
......@@ -107,8 +107,10 @@ allow domain libart_file:file { execute read open getattr };
auditallow {
domain
-appdomain
-debuggerd
-dex2oat
-dumpstate
-profman
-recovery
-zygote
} libart_file:file { execute read open getattr };
......
......@@ -2,6 +2,8 @@
type profman, domain;
type profman_exec, exec_type, file_type;
allow profman libart_file:file r_file_perms;
allow profman user_profile_data_file:file { getattr read write lock };
# Dumping profile info opens the application APK file for pretty printing.
......@@ -14,4 +16,8 @@ allow profman profman_dump_data_file:file { write };
allow profman installd:fd use;
###
### neverallow rules
###
neverallow profman app_data_file:notdevfile_class_set open;
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment