Skip to content
Snippets Groups Projects
Commit 997d4a18 authored by Stephen Smalley's avatar Stephen Smalley
Browse files

Drop dontaudit sys_admin rule from rild.


Old Android kernels (e.g. kernel/goldfish android-2.6.29 commit 2bda29)
fell back to a CAP_SYS_ADMIN check even before checking uids if the cgroup
subsystem did not define its own can_attach handler.  This doesn't appear
to have ever been the case of mainline, and is not true of the 3.4 Android
kernels.  So we no longer need to dontaudit sys_admin to avoid log noise.

Change-Id: I2faade6665a4adad91472c95f94bd922a449b240
Signed-off-by: default avatarStephen Smalley <sds@tycho.nsa.gov>
parent 1cb990de
No related branches found
No related tags found
No related merge requests found
...@@ -24,7 +24,6 @@ allow rild sdcard_type:dir r_dir_perms; ...@@ -24,7 +24,6 @@ allow rild sdcard_type:dir r_dir_perms;
allow rild system_data_file:dir r_dir_perms; allow rild system_data_file:dir r_dir_perms;
allow rild system_data_file:file r_file_perms; allow rild system_data_file:file r_file_perms;
allow rild system_file:file x_file_perms; allow rild system_file:file x_file_perms;
dontaudit rild self:capability sys_admin;
# property service # property service
allow rild rild_prop:property_service set; allow rild rild_prop:property_service set;
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment