Skip to content
Snippets Groups Projects
Commit cc82d194 authored by Zheng Zhang's avatar Zheng Zhang
Browse files

Limit mediaserver access to vendor_app_file

mediaserver is receiving a file passed as a file descriptor. Just read
and map is enough, and open should not be allowed for mediaserver.

Bug: 78436043
parent 50ca0a0d
No related branches found
No related tags found
No related merge requests found
......@@ -96,7 +96,7 @@ allow mediaserver oemfs:dir search;
allow mediaserver oemfs:file r_file_perms;
# /vendor apk access
allow mediaserver vendor_app_file:file r_file_perms;
allow mediaserver vendor_app_file:file { read map };
use_drmservice(mediaserver)
allow mediaserver drmserver:drmservice {
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment