Skip to content
Snippets Groups Projects
Commit 21b4a925 authored by Jeff Vander Stoep's avatar Jeff Vander Stoep
Browse files

domain_deprecated: Remove access to /data/app

Logs indicate that all processes that require access already have it.

Bug: 28760354
Test: build
Change-Id: I8533308d0e5f9bf20e542f8435d70ba7755b4938
parent 6775ee15
No related branches found
No related tags found
No related merge requests found
# rules removed from the domain attribute
# Read apk files under /data/app.
allow domain_deprecated apk_data_file:dir { getattr search };
allow domain_deprecated apk_data_file:file r_file_perms;
allow domain_deprecated apk_data_file:lnk_file r_file_perms;
userdebug_or_eng(`
auditallow {
domain_deprecated
-appdomain
-dex2oat
-installd
-system_server
} apk_data_file:dir { getattr search };
auditallow {
domain_deprecated
-appdomain
-dex2oat
-installd
-system_server
} apk_data_file:file r_file_perms;
auditallow {
domain_deprecated
-appdomain
-dex2oat
-installd
-system_server
} apk_data_file:lnk_file r_file_perms;
')
# Read access to pseudo filesystems.
r_dir_file(domain_deprecated, proc)
r_dir_file(domain_deprecated, sysfs)
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment