aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorTreehugger Robot2018-04-13 15:44:44 -0500
committerGerrit Code Review2018-04-13 15:44:44 -0500
commitbf41ff48cf4597bd42ff7da631f56b7d5738bfa2 (patch)
treecac1636a8952819ddff175bfe9458ae85c88f821
parent9047a4de89e6cb1c70c0bbd073666bc857724178 (diff)
parentfc870ce954ca3945b90c4034ab446f775aac2139 (diff)
downloadsystem-sepolicy-bf41ff48cf4597bd42ff7da631f56b7d5738bfa2.tar.gz
system-sepolicy-bf41ff48cf4597bd42ff7da631f56b7d5738bfa2.tar.xz
system-sepolicy-bf41ff48cf4597bd42ff7da631f56b7d5738bfa2.zip
Merge "Allow some vold_prepare_subdirs denials."
-rw-r--r--private/vold_prepare_subdirs.te10
1 files changed, 6 insertions, 4 deletions
diff --git a/private/vold_prepare_subdirs.te b/private/vold_prepare_subdirs.te
index af1f4423..badbb71f 100644
--- a/private/vold_prepare_subdirs.te
+++ b/private/vold_prepare_subdirs.te
@@ -7,12 +7,14 @@ allow vold_prepare_subdirs devpts:chr_file rw_file_perms;
7allow vold_prepare_subdirs vold:fd use; 7allow vold_prepare_subdirs vold:fd use;
8allow vold_prepare_subdirs vold:fifo_file { read write }; 8allow vold_prepare_subdirs vold:fifo_file { read write };
9allow vold_prepare_subdirs file_contexts_file:file r_file_perms; 9allow vold_prepare_subdirs file_contexts_file:file r_file_perms;
10allow vold_prepare_subdirs self:global_capability_class_set { chown dac_override }; 10allow vold_prepare_subdirs self:global_capability_class_set { chown dac_override fowner };
11allow vold_prepare_subdirs self:process setfscreate; 11allow vold_prepare_subdirs self:process setfscreate;
12allow vold_prepare_subdirs { 12allow vold_prepare_subdirs {
13 system_data_file 13 system_data_file
14 vendor_data_file 14 vendor_data_file
15}:dir { open read write add_name remove_name }; 15}:dir { open read write add_name remove_name relabelfrom };
16allow vold_prepare_subdirs vold_data_file:dir { create open read write search getattr setattr remove_name rmdir }; 16allow vold_prepare_subdirs system_data_file:file getattr;
17allow vold_prepare_subdirs vold_data_file:dir { create open read write search getattr setattr remove_name rmdir relabelto };
17allow vold_prepare_subdirs vold_data_file:file { getattr unlink }; 18allow vold_prepare_subdirs vold_data_file:file { getattr unlink };
18allow vold_prepare_subdirs storaged_data_file:dir create_dir_perms; 19allow vold_prepare_subdirs storaged_data_file:dir { create_dir_perms relabelto };
20allow vold_prepare_subdirs storaged_data_file:file getattr;