Skip to content
Snippets Groups Projects
Commit 2ffd52a4 authored by Stephen Smalley's avatar Stephen Smalley Committed by Android Git Automerger
Browse files

am 043b9027: Confine watchdogd, but leave it permissive for now.

* commit '043b9027':
  Confine watchdogd, but leave it permissive for now.
parents 6af0cc24 043b9027
No related branches found
No related tags found
No related merge requests found
# watchdogd seclabel is specified in init.<board>.rc
type watchdogd, domain;
unconfined_domain(watchdogd)
allow watchdogd rootfs:file entrypoint;
permissive watchdogd;
allow watchdogd rootfs:file { entrypoint r_file_perms };
allow watchdogd self:capability mknod;
allow watchdogd device:dir { add_name write remove_name };
allow watchdogd watchdog_device:chr_file rw_file_perms;
# because of /dev/__kmsg__ and /dev/__null__
write_klog(watchdogd)
type_transition watchdogd device:chr_file null_device "__null__";
allow watchdogd null_device:chr_file { create unlink };
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment