diff options
author | Nick Kralevich <nnk@google.com> | 2014-09-03 16:56:41 -0700 |
---|---|---|
committer | Nick Kralevich <nnk@google.com> | 2014-09-06 11:23:11 -0700 |
commit | a42dc5df701bcc46be6088f54367d17acd5bd466 (patch) | |
tree | f014ae3fb910b6400a580ebd3f6602ac4d2f7e3f /sepolicy/file_contexts | |
parent | 3b8134bf4d53da66f1986e386d753fd1e57cf398 (diff) | |
download | shamu-a42dc5df701bcc46be6088f54367d17acd5bd466.tar.gz |
ss_ramdump: start enforcing SELinux rules and fix denials
Remove the permissive line and start enforcing SELinux rules
for the ss_ramdump process.
Also addresses the following denials:
type=1400 audit(1021853.259:5): avc: denied { read } for pid=349 comm="subsystem_ramdu" name="ramdump_vpu" dev="tmpfs" ino=9185 scontext=u:r:ss_ramdump:s0 tcontext=u:object_r:ramdump_device:s0 tclass=chr_file permissive=0
type=1400 audit(0.0:60): avc: denied { dac_override } for comm="subsystem_ramdu" capability=1 scontext=u:r:ss_ramdump:s0 tcontext=u:r:ss_ramdump:s0 tclass=capability permissive=1
type=1400 audit(0.0:61): avc: denied { write } for comm="subsystem_ramdu" name="tombstones" dev="dm-0" ino=2714433 scontext=u:r:ss_ramdump:s0 tcontext=u:object_r:tombstone_data_file:s0 tclass=dir permissive=1
type=1400 audit(0.0:62): avc: denied { add_name } for comm="subsystem_ramdu" name="ramdump_venus.elf" scontext=u:r:ss_ramdump:s0 tcontext=u:object_r:tombstone_data_file:s0 tclass=dir permissive=1
type=1400 audit(0.0:63): avc: denied { create } for comm="subsystem_ramdu" name="ramdump_venus.elf" scontext=u:r:ss_ramdump:s0 tcontext=u:object_r:tombstone_data_file:s0 tclass=file permissive=1
type=1400 audit(0.0:64): avc: denied { write open } for comm="subsystem_ramdu" path="/data/tombstones/ramdump_venus.elf" dev="dm-0" ino=2714442 scontext=u:r:ss_ramdump:s0 tcontext=u:object_r:tombstone_data_file:s0 tclass=file permissive=1
Bug: 16319212
Change-Id: If9997afba49903c474d053d1b896a1b640192a2e
Diffstat (limited to 'sepolicy/file_contexts')
-rw-r--r-- | sepolicy/file_contexts | 1 |
1 files changed, 1 insertions, 0 deletions
diff --git a/sepolicy/file_contexts b/sepolicy/file_contexts index cb792141..75996dcb 100644 --- a/sepolicy/file_contexts +++ b/sepolicy/file_contexts @@ -42,6 +42,7 @@ # Should only be on userdebug device /dev/diag u:object_r:diag_device:s0 /dev/ttydiag2 u:object_r:diag_device:s0 +/dev/ramdump_.* u:object_r:ramdump_device:s0 # MSM camera related /dev/media([0-9])+ u:object_r:camera_device:s0 |