Skip to content
Snippets Groups Projects
Commit 4fa88f87 authored by Yabin Cui's avatar Yabin Cui Committed by android-build-merger
Browse files

Make /proc/sys/kernel/perf_event_max_sample_rate accessible to untrusted_app.

am: 5b15baeb

Change-Id: Ic6ce0d595986c64590f85e8f39454585f42c1504
parents 3227d2ce 5b15baeb
No related branches found
No related tags found
No related merge requests found
...@@ -22,6 +22,7 @@ genfscon proc /sys/kernel/hotplug u:object_r:usermodehelper:s0 ...@@ -22,6 +22,7 @@ genfscon proc /sys/kernel/hotplug u:object_r:usermodehelper:s0
genfscon proc /sys/kernel/kptr_restrict u:object_r:proc_security:s0 genfscon proc /sys/kernel/kptr_restrict u:object_r:proc_security:s0
genfscon proc /sys/kernel/modprobe u:object_r:usermodehelper:s0 genfscon proc /sys/kernel/modprobe u:object_r:usermodehelper:s0
genfscon proc /sys/kernel/modules_disabled u:object_r:proc_security:s0 genfscon proc /sys/kernel/modules_disabled u:object_r:proc_security:s0
genfscon proc /sys/kernel/perf_event_max_sample_rate u:object_r:proc_perf:s0
genfscon proc /sys/kernel/poweroff_cmd u:object_r:usermodehelper:s0 genfscon proc /sys/kernel/poweroff_cmd u:object_r:usermodehelper:s0
genfscon proc /sys/kernel/randomize_va_space u:object_r:proc_security:s0 genfscon proc /sys/kernel/randomize_va_space u:object_r:proc_security:s0
genfscon proc /sys/kernel/usermodehelper u:object_r:usermodehelper:s0 genfscon proc /sys/kernel/usermodehelper u:object_r:usermodehelper:s0
......
...@@ -118,6 +118,9 @@ allow domain proc_cpuinfo:file r_file_perms; ...@@ -118,6 +118,9 @@ allow domain proc_cpuinfo:file r_file_perms;
# jemalloc needs to read /proc/sys/vm/overcommit_memory # jemalloc needs to read /proc/sys/vm/overcommit_memory
allow domain proc_overcommit_memory:file r_file_perms; allow domain proc_overcommit_memory:file r_file_perms;
# profiling needs to read /proc/sys/kernel/perf_event_max_sample_rate
allow domain proc_perf:file r_file_perms;
# toybox loads libselinux which stats /sys/fs/selinux/ # toybox loads libselinux which stats /sys/fs/selinux/
allow domain selinuxfs:dir search; allow domain selinuxfs:dir search;
allow domain selinuxfs:file getattr; allow domain selinuxfs:file getattr;
......
...@@ -18,6 +18,7 @@ type proc_iomem, fs_type; ...@@ -18,6 +18,7 @@ type proc_iomem, fs_type;
type proc_meminfo, fs_type; type proc_meminfo, fs_type;
type proc_misc, fs_type; type proc_misc, fs_type;
type proc_net, fs_type; type proc_net, fs_type;
type proc_perf, fs_type;
type proc_stat, fs_type; type proc_stat, fs_type;
type proc_sysrq, fs_type; type proc_sysrq, fs_type;
type proc_timer, fs_type; type proc_timer, fs_type;
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment