Skip to content
Snippets Groups Projects
Commit 33da6091 authored by Stephen Smalley's avatar Stephen Smalley
Browse files

Allow all domains to read /dev symlinks.


Change-Id: I448a5553937a98775178b94f289ccb45ae862876
Signed-off-by: default avatarStephen Smalley <sds@tycho.nsa.gov>
parent c37856c4
No related branches found
No related tags found
No related merge requests found
......@@ -23,9 +23,6 @@ allow appdomain file_type:dir_file_class_set getattr;
allow appdomain dev_type:dir_file_class_set getattr;
allow appdomain fs_type:dir_file_class_set getattr;
# Read permission over link file to devices.
allow appdomain dev_type:lnk_file read;
# Tries to open /dev/alarm for writing but expects failure.
dontaudit appdomain alarm_device:chr_file write;
......
......@@ -40,6 +40,7 @@ allow domain rootfs:lnk_file { read getattr };
# Device accesses.
allow domain device:dir search;
allow domain dev_type:lnk_file read;
allow domain devpts:dir search;
allow domain device:file read;
allow domain socket_device:dir search;
......
......@@ -22,7 +22,6 @@ allow rild bluetooth_efs_file:file r_file_perms;
allow rild bluetooth_efs_file:dir r_dir_perms;
allow rild radio_data_file:dir r_dir_perms;
allow rild radio_data_file:file rw_file_perms;
allow rild radio_device:lnk_file r_file_perms;
allow rild sdcard_type:dir r_dir_perms;
allow rild system_data_file:dir create_dir_perms;
allow rild system_data_file:file create_file_perms;
......
......@@ -7,7 +7,6 @@ typeattribute vold mlstrustedsubject;
allow vold system_file:file x_file_perms;
allow vold block_device:dir create_dir_perms;
allow vold block_device:blk_file create_file_perms;
allow vold block_device:lnk_file read;
allow vold devpts:chr_file rw_file_perms;
allow vold rootfs:dir mounton;
allow vold sdcard_type:dir mounton;
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment