Skip to content
Snippets Groups Projects
Commit 62a1b236 authored by Jorge Lucangeli Obes's avatar Jorge Lucangeli Obes
Browse files

system_server: Report dalvikcache_data_file execute violations.

With build/core eaa9d88cf, system_server should not be loading code
from /data. Add an auditallow rule to report violations.

Bug: 37214733
Test: Boot marlin, no SELinux audit lines for system_server.
Change-Id: I2e25eb144503274025bd4fc9bb519555851f6521
(cherry picked from commit 665128fa)
parent 976fb16b
No related branches found
No related tags found
No related merge requests found
......@@ -18,6 +18,10 @@ allow system_server zygote_tmpfs:file read;
# For art.
allow system_server dalvikcache_data_file:dir r_dir_perms;
allow system_server dalvikcache_data_file:file { r_file_perms execute };
userdebug_or_eng(`
# Report dalvikcache_data_file:file execute violations.
auditallow system_server dalvikcache_data_file:file execute;
')
# /data/resource-cache
allow system_server resourcecache_data_file:file r_file_perms;
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment