Skip to content
Snippets Groups Projects
Commit 86987a01 authored by Jeff Sharkey's avatar Jeff Sharkey Committed by Android (Google) Code Review
Browse files

Merge "New "selinux.restorecon" control property." into mnc-dev

parents ba8821b0 7617cd48
No related branches found
No related tags found
No related merge requests found
...@@ -21,6 +21,7 @@ type ctl_bugreport_prop, property_type; ...@@ -21,6 +21,7 @@ type ctl_bugreport_prop, property_type;
type ctl_console_prop, property_type; type ctl_console_prop, property_type;
type audio_prop, property_type; type audio_prop, property_type;
type logd_prop, property_type; type logd_prop, property_type;
type restorecon_prop, property_type;
type security_prop, property_type; type security_prop, property_type;
type bluetooth_prop, property_type; type bluetooth_prop, property_type;
type pan_result_prop, property_type; type pan_result_prop, property_type;
......
...@@ -41,7 +41,8 @@ persist.service.bdroid. u:object_r:bluetooth_prop:s0 ...@@ -41,7 +41,8 @@ persist.service.bdroid. u:object_r:bluetooth_prop:s0
persist.security. u:object_r:system_prop:s0 persist.security. u:object_r:system_prop:s0
# selinux non-persistent properties # selinux non-persistent properties
selinux. u:object_r:security_prop:s0 selinux.restorecon_recursive u:object_r:restorecon_prop:s0
selinux. u:object_r:security_prop:s0
# default property context # default property context
* u:object_r:default_prop:s0 * u:object_r:default_prop:s0
......
...@@ -111,6 +111,7 @@ allow vold kernel:process setsched; ...@@ -111,6 +111,7 @@ allow vold kernel:process setsched;
set_prop(vold, vold_prop) set_prop(vold, vold_prop)
set_prop(vold, powerctl_prop) set_prop(vold, powerctl_prop)
set_prop(vold, ctl_fuse_prop) set_prop(vold, ctl_fuse_prop)
set_prop(vold, restorecon_prop)
# ASEC # ASEC
allow vold asec_image_file:file create_file_perms; allow vold asec_image_file:file create_file_perms;
...@@ -159,3 +160,4 @@ neverallow { domain -vold } vold_data_file:dir ~{ open create read getattr setat ...@@ -159,3 +160,4 @@ neverallow { domain -vold } vold_data_file:dir ~{ open create read getattr setat
neverallow { domain -vold } vold_data_file:notdevfile_class_set ~{ relabelto getattr }; neverallow { domain -vold } vold_data_file:notdevfile_class_set ~{ relabelto getattr };
neverallow { domain -vold -init } vold_data_file:dir *; neverallow { domain -vold -init } vold_data_file:dir *;
neverallow { domain -vold -init } vold_data_file:notdevfile_class_set *; neverallow { domain -vold -init } vold_data_file:notdevfile_class_set *;
neverallow { domain -vold -init } restorecon_prop:property_service set;
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment