diff --git a/public/domain_deprecated.te b/public/domain_deprecated.te index f5231fbb3f975b8e8bff79956590e7157d99e4d7..f989ea1e7a0ec608a5308d192f7f2dfbb84f5be2 100644 --- a/public/domain_deprecated.te +++ b/public/domain_deprecated.te @@ -1,21 +1,5 @@ # rules removed from the domain attribute -# Search /storage/emulated tmpfs mount. -allow { domain_deprecated -installd } tmpfs:dir r_dir_perms; -userdebug_or_eng(` -auditallow { - domain_deprecated - -appdomain - -installd - -recovery - -sdcardd - -surfaceflinger - -system_server - -vold - -zygote -} tmpfs:dir r_dir_perms; -') - # Root fs. allow domain_deprecated rootfs:dir r_dir_perms; allow domain_deprecated rootfs:file r_file_perms; diff --git a/public/dumpstate.te b/public/dumpstate.te index ee27cbee7c78ea966b420b59ebe5a471f585ab76..66eaa1f2c2c22ef6bd8641255f1001e69434943c 100644 --- a/public/dumpstate.te +++ b/public/dumpstate.te @@ -82,7 +82,7 @@ allow dumpstate sysfs_usb:file w_file_perms; allow dumpstate qtaguid_proc:file r_file_perms; allow dumpstate debugfs:file r_file_perms; # df for /storage/emulated needs search -allow dumpstate { storage_file block_device }:dir { search getattr }; +allow dumpstate { block_device storage_file tmpfs }:dir { search getattr }; allow dumpstate fuse_device:chr_file getattr; allow dumpstate { dm_device cache_block_device }:blk_file getattr;