diff options
author | Geremy Condra <gcondra@google.com> | 2013-09-05 23:49:50 +0000 |
---|---|---|
committer | Gerrit Code Review <noreply-gerritcodereview@google.com> | 2013-09-05 23:49:51 +0000 |
commit | 21d13e9b667bbd3c1837881e0febe7e7d0931ed9 (patch) | |
tree | b2fc6d063a1f41a94c4c9a85039f4926ed33518b | |
parent | 66826d5e15cbaae5a0ecd613f5148003927e79ab (diff) | |
parent | 217f8afc188d4e1f393b0fa36a7dda2d6e0273ca (diff) | |
download | sepolicy-21d13e9b667bbd3c1837881e0febe7e7d0931ed9.tar.gz |
Merge "Fix more long-tail denials."
-rw-r--r-- | isolated_app.te | 6 | ||||
-rw-r--r-- | kernel.te | 1 | ||||
-rw-r--r-- | system.te | 5 |
3 files changed, 12 insertions, 0 deletions
diff --git a/isolated_app.te b/isolated_app.te index 77f14d3..1b33484 100644 --- a/isolated_app.te +++ b/isolated_app.te @@ -21,3 +21,9 @@ r_dir_file(appdomain, isolated_app) # Chrome works, may need to be updated as more apps using isolated services # are examined. allow isolated_app appdomain:unix_stream_socket { read write }; + +allow isolated_app dalvikcache_data_file:file execute; +allow isolated_app apk_data_file:dir getattr; + +allow isolated_app init:unix_stream_socket { read write getattr getopt }; +allow isolated_app init_tmpfs:file read; @@ -6,3 +6,4 @@ unconfined_domain(kernel) relabelto_domain(kernel) allow kernel {fs_type dev_type file_type}:dir_file_class_set relabelto; +allow kernel unlabeled:filesystem mount; @@ -14,5 +14,10 @@ allow system self:zygote { specifyids specifyrlimits specifyseinfo }; allow system backup_data_file:dir relabelto; allow system cache_backup_file:dir relabelto; +allow system anr_data_file:dir relabelto; +allow system system_data_file:dir relabelto; allow system apk_data_file:file relabelto; allow system apk_tmp_file:file relabelto; +allow system cache_backup_file:file relabelto; +allow system apk_private_tmp_file:file relabelto; +allow system wallpaper_file:file relabelto; |