aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorGeremy Condra <gcondra@google.com>2013-09-05 23:49:50 +0000
committerGerrit Code Review <noreply-gerritcodereview@google.com>2013-09-05 23:49:51 +0000
commit21d13e9b667bbd3c1837881e0febe7e7d0931ed9 (patch)
treeb2fc6d063a1f41a94c4c9a85039f4926ed33518b
parent66826d5e15cbaae5a0ecd613f5148003927e79ab (diff)
parent217f8afc188d4e1f393b0fa36a7dda2d6e0273ca (diff)
downloadsepolicy-21d13e9b667bbd3c1837881e0febe7e7d0931ed9.tar.gz
Merge "Fix more long-tail denials."
-rw-r--r--isolated_app.te6
-rw-r--r--kernel.te1
-rw-r--r--system.te5
3 files changed, 12 insertions, 0 deletions
diff --git a/isolated_app.te b/isolated_app.te
index 77f14d3..1b33484 100644
--- a/isolated_app.te
+++ b/isolated_app.te
@@ -21,3 +21,9 @@ r_dir_file(appdomain, isolated_app)
# Chrome works, may need to be updated as more apps using isolated services
# are examined.
allow isolated_app appdomain:unix_stream_socket { read write };
+
+allow isolated_app dalvikcache_data_file:file execute;
+allow isolated_app apk_data_file:dir getattr;
+
+allow isolated_app init:unix_stream_socket { read write getattr getopt };
+allow isolated_app init_tmpfs:file read;
diff --git a/kernel.te b/kernel.te
index 023e457..e313587 100644
--- a/kernel.te
+++ b/kernel.te
@@ -6,3 +6,4 @@ unconfined_domain(kernel)
relabelto_domain(kernel)
allow kernel {fs_type dev_type file_type}:dir_file_class_set relabelto;
+allow kernel unlabeled:filesystem mount;
diff --git a/system.te b/system.te
index 24d4a67..b096b68 100644
--- a/system.te
+++ b/system.te
@@ -14,5 +14,10 @@ allow system self:zygote { specifyids specifyrlimits specifyseinfo };
allow system backup_data_file:dir relabelto;
allow system cache_backup_file:dir relabelto;
+allow system anr_data_file:dir relabelto;
+allow system system_data_file:dir relabelto;
allow system apk_data_file:file relabelto;
allow system apk_tmp_file:file relabelto;
+allow system cache_backup_file:file relabelto;
+allow system apk_private_tmp_file:file relabelto;
+allow system wallpaper_file:file relabelto;