Skip to content
Snippets Groups Projects
Commit 96a85d12 authored by Jeff Vander Stoep's avatar Jeff Vander Stoep
Browse files

app: audit usage of ion ioctls

Test: builds and boots on Bullhead with no selinux audit messages.

Bug: 29795149
Bug: 30400942
Change-Id: I93295424a03488234b233d5e2f86d3bf329e53fd
parent cd623e34
No related branches found
No related tags found
No related merge requests found
......@@ -239,7 +239,9 @@ allowxperm { appdomain -bluetooth } self:{ rawip_socket tcp_socket udp_socket }
allow { appdomain -isolated_app } ion_device:chr_file rw_file_perms;
# TODO is write really necessary ?
auditallow { appdomain -isolated_app } ion_device:chr_file { write append };
auditallow appdomain ion_device:chr_file { write append };
# TODO audit ion ioctl usage by apps
auditallow appdomain ion_device:chr_file ioctl;
# TODO: switch to meminfo service
allow appdomain proc_meminfo:file r_file_perms;
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment