diff --git a/app.te b/app.te index 993c025536e627cb03b933986e6b93736fa2b23d..19f9b61518b0d2d267af357a86c2f95fc9acd097 100644 --- a/app.te +++ b/app.te @@ -226,10 +226,6 @@ allow appdomain runas_exec:file getattr; selinux_check_access(appdomain) selinux_check_context(appdomain) -# appdomain should not be accessing information on /sys -auditallow { appdomain userdebug_or_eng(`-su') } sysfs:dir { open getattr read ioctl }; -auditallow { appdomain userdebug_or_eng(`-su') } sysfs:file r_file_perms; - # Apps receive an open tun fd from the framework for # device traffic. Do not allow untrusted app to directly open tun_device allow { appdomain -isolated_app } tun_device:chr_file { read write getattr ioctl append };