Explicitly label vold dependecies in /proc
1. Labeled: /proc/cmdline -> proc_cmdline 2. Removed access to proc label from vold domain. 3. Added access proc_cmdline to these domains: init, kernel, vold 4. Also, added proc_drop_caches access to vold. Bug: 66497047 Test: device boots without selinux denials to new labels Change-Id: Ic88d11b7e56b07c0e8bd874e7f72788922a218e3
Showing
- private/compat/26.0/26.0.cil 1 addition, 1 deletionprivate/compat/26.0/26.0.cil
- private/genfs_contexts 1 addition, 0 deletionsprivate/genfs_contexts
- public/file.te 1 addition, 0 deletionspublic/file.te
- public/init.te 3 additions, 0 deletionspublic/init.te
- public/kernel.te 1 addition, 0 deletionspublic/kernel.te
- public/vold.te 2 additions, 1 deletionpublic/vold.te
Loading
Please register or sign in to comment