diff options
author | Jeff Vander Stoep <jeffv@google.com> | 2018-01-30 13:25:07 -0800 |
---|---|---|
committer | Jeff Vander Stoep <jeffv@google.com> | 2018-01-30 13:52:17 -0800 |
commit | a590164dc8fa14ef345aba56c0f0ba36b1c36046 (patch) | |
tree | 28f65fb5b76a3adcc0e16fa73b3cb58477572569 | |
parent | f986c1804711e2d9482bf56a4544888715384bf3 (diff) | |
download | bullhead-a590164dc8fa14ef345aba56c0f0ba36b1c36046.tar.gz |
Correctly label data types
Data outside /data/vendor must have the core_data_file_type
attribute.
Test: build (this is a build time test)
Bug: 34980020
Change-Id: I372c80da64abc26d8dd1478d208074de25d88357
-rw-r--r-- | sepolicy/file.te | 10 | ||||
-rw-r--r-- | sepolicy/time_daemon.te | 2 |
2 files changed, 6 insertions, 6 deletions
diff --git a/sepolicy/file.te b/sepolicy/file.te index 21dcd0d..2dddda5 100644 --- a/sepolicy/file.te +++ b/sepolicy/file.te @@ -19,18 +19,18 @@ type mpdecision_socket, file_type; type qmuxd_socket, file_type; # location file types -type location_data_file, file_type, data_file_type; +type location_data_file, file_type, data_file_type, core_data_file_type; type location_app_data_file, file_type, data_file_type; # Socket node needed by ims_data daemon type ims_socket, file_type; -type ramdump_data_file, file_type, data_file_type; -type diag_logs, file_type, data_file_type, mlstrustedobject; +type ramdump_data_file, file_type, data_file_type, core_data_file_type; +type diag_logs, file_type, data_file_type, core_data_file_type, mlstrustedobject; -type perfd_data_file, file_type, data_file_type; +type perfd_data_file, file_type, data_file_type, core_data_file_type; -type cnd_data_file, file_type, data_file_type; +type cnd_data_file, file_type, data_file_type, core_data_file_type; type nfc_vendor_data_file, file_type, data_file_type; diff --git a/sepolicy/time_daemon.te b/sepolicy/time_daemon.te index 6ec1100..84463f5 100644 --- a/sepolicy/time_daemon.te +++ b/sepolicy/time_daemon.te @@ -1,7 +1,7 @@ # Policies for time daemon type time_daemon, domain, device_domain_deprecated; type time_daemon_exec, exec_type, file_type; -type time_data_file, file_type, data_file_type; +type time_data_file, file_type, data_file_type, core_data_file_type; # Make transition to its own time_daemon domain from init init_daemon_domain(time_daemon) |