Skip to content
Snippets Groups Projects
Commit 5e901bbe authored by Joel Scherpelz's avatar Joel Scherpelz
Browse files

Allow dumpstate to acquire xtables.lock

iptables recently changed its behavior to strictly require xtables.lock.
dumpstate selinux policy must be updated to allow access.

Bug: 37648320
Test: dumpstate succeeds with no avc: denied ... xtables.lock messages
Change-Id: Ic7e243739f375a60fa14fe67fac910d31d978ffd
(cherry picked from commit ca097979)
parent 327d7cb9
No related branches found
No related tags found
No related merge requests found
...@@ -5,6 +5,9 @@ init_daemon_domain(dumpstate) ...@@ -5,6 +5,9 @@ init_daemon_domain(dumpstate)
# Execute and transition to the vdc domain # Execute and transition to the vdc domain
domain_auto_trans(dumpstate, vdc_exec, vdc) domain_auto_trans(dumpstate, vdc_exec, vdc)
# Acquire advisory lock on /system/etc/xtables.lock from ip[6]tables
allow dumpstate system_file:file lock;
# TODO: deal with tmpfs_domain pub/priv split properly # TODO: deal with tmpfs_domain pub/priv split properly
allow dumpstate dumpstate_tmpfs:file execute; allow dumpstate dumpstate_tmpfs:file execute;
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment