diff --git a/private/system_server.te b/private/system_server.te index eaa141289fdf8719bc2791759f96117e1eb6c886..c10a617ef7ccfb6aaf68d8fb3d159d423adc1ba4 100644 --- a/private/system_server.te +++ b/private/system_server.te @@ -787,8 +787,7 @@ neverallow system_server { domain -system_server }:process ptrace; # CAP_SYS_RESOURCE was traditionally needed for sensitive /proc/PID # file read access. However, that is now unnecessary (b/34951864) -# This neverallow can be removed after b/34951864 is fixed. -neverallow system_server system_server:capability sys_resource; +neverallow system_server system_server:global_capability_class_set sys_resource; # TODO(b/67468181): Remove following lines upon resolution of this bug dontaudit system_server statscompanion_service:service_manager { add find };