Skip to content
Snippets Groups Projects
Commit 0b80f4dc authored by dcashman's avatar dcashman
Browse files

Remove appdomain sysfs auditallow.

Large numbers of denials have been collected.  Remove from logging until
further action is taken to address existing denials and remove sysfs
access from additional appdomains.

Change-Id: Ia7ad6264d85490824089b5074bf9c22303cc864a
parent 3ec34ceb
No related branches found
No related tags found
No related merge requests found
......@@ -226,10 +226,6 @@ allow appdomain runas_exec:file getattr;
selinux_check_access(appdomain)
selinux_check_context(appdomain)
# appdomain should not be accessing information on /sys
auditallow { appdomain userdebug_or_eng(`-su') } sysfs:dir { open getattr read ioctl };
auditallow { appdomain userdebug_or_eng(`-su') } sysfs:file r_file_perms;
# Apps receive an open tun fd from the framework for
# device traffic. Do not allow untrusted app to directly open tun_device
allow { appdomain -isolated_app } tun_device:chr_file { read write getattr ioctl append };
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment