Skip to content
Snippets Groups Projects
  • Joel Galenson's avatar
    Allow some vold_prepare_subdirs denials. · 855dd5a8
    Joel Galenson authored
    This addresses the following denials:
    
    avc: denied { fowner } for comm="rm" scontext=u:r:vold_prepare_subdirs:s0 tcontext=u:r:vold_prepare_subdirs:s0 tclass=capability
    avc: denied { getattr } for comm="rm" scontext=u:r:vold_prepare_subdirs:s0 tcontext=u:object_r:storaged_data_file:s0 tclass=file
    avc: denied { relabelfrom } for comm="vold_prepare_su" name="storaged" scontext=u:r:vold_prepare_subdirs:s0 tcontext=u:object_r:system_data_file:s0 tclass=dir
    avc: denied { getattr } for comm="rm" scontext=u:r:vold_prepare_subdirs:s0 tcontext=u:object_r:system_data_file:s0 tclass=file
    
    Bug: 77875245
    Test: Boot device.
    Change-Id: Id67bc99f151a6ccb9619bbfb7080452956405121
    Test: Mislabel directories used by vold_prepare_subdirs, reboot, and
    ensure it can relabel them without denials.
    Test: Add user, reboot, delete user, reboot, observe no denials.
    855dd5a8