Skip to content
Snippets Groups Projects
  • Tom Cherry's avatar
    938ab05d
    Allow init to execute services marked with seclabel u:r:su:s0 in userdebug/eng · 938ab05d
    Tom Cherry authored
    This is do aid developers pushing debug services to not need to modify
    the underlying SEPolicy
    
    avc: denied { transition } for comm="init" path="/system/bin/awk"
    dev="dm-0" ino=1934 scontext=u:r:init:s0 tcontext=u:r:su:s0
    tclass=process
    avc: denied { rlimitinh } for comm="awk" scontext=u:r:init:s0
    tcontext=u:r:su:s0 tclass=process
    avc: denied { siginh } for comm="awk" scontext=u:r:init:s0
    tcontext=u:r:su:s0 tclass=process
    avc: denied { noatsecure } for comm="awk" scontext=u:r:init:s0
    tcontext=u:r:su:s0 tclass=process
    
    Test: init can execute a system_file marked with seclabel u:r:su:s0
    Change-Id: I85d9528341fe08dbb2fb9a91e34a41f41aa093be
    938ab05d
    History
    Allow init to execute services marked with seclabel u:r:su:s0 in userdebug/eng
    Tom Cherry authored
    This is do aid developers pushing debug services to not need to modify
    the underlying SEPolicy
    
    avc: denied { transition } for comm="init" path="/system/bin/awk"
    dev="dm-0" ino=1934 scontext=u:r:init:s0 tcontext=u:r:su:s0
    tclass=process
    avc: denied { rlimitinh } for comm="awk" scontext=u:r:init:s0
    tcontext=u:r:su:s0 tclass=process
    avc: denied { siginh } for comm="awk" scontext=u:r:init:s0
    tcontext=u:r:su:s0 tclass=process
    avc: denied { noatsecure } for comm="awk" scontext=u:r:init:s0
    tcontext=u:r:su:s0 tclass=process
    
    Test: init can execute a system_file marked with seclabel u:r:su:s0
    Change-Id: I85d9528341fe08dbb2fb9a91e34a41f41aa093be