Skip to content
Snippets Groups Projects
Commit 3e6da147 authored by dcashman's avatar dcashman Committed by Nick Kralevich
Browse files

Enable selinux read_policy for adb pull.

Remove permission from appdomain.

(cherry picked from commit 309cc668)

Bug: 16866291

Change-Id: I37936fed33c337e1ab2816258c2aff52700af116
parent 9ac7df22
No related branches found
No related tags found
No related merge requests found
......@@ -69,6 +69,8 @@ allow adbd appdomain:unix_stream_socket connectto;
allow adbd zygote_exec:file r_file_perms;
allow adbd system_file:file r_file_perms;
allow adbd kernel:security read_policy;
service_manager_local_audit_domain(adbd)
auditallow adbd {
service_manager_type
......
......@@ -166,8 +166,6 @@ allow appdomain runas_exec:file getattr;
# Check SELinux policy and contexts.
selinux_check_access(appdomain)
selinux_check_context(appdomain)
# Enable reading of current selinux policy file
allow appdomain kernel:security read_policy;
# Validate that each process is running in the correct security context.
allow appdomain domain:process getattr;
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment