Merge "sepolicy: Fix 'avc denied' issues for the emulators"
This commit is contained in:
@@ -1,3 +1,5 @@
|
|||||||
# For /sys/qemu_trace files in the emulator.
|
# For /sys/qemu_trace files in the emulator.
|
||||||
allow domain sysfs_writable:file rw_file_perms;
|
allow domain sysfs_writable:file rw_file_perms;
|
||||||
allow domain qemu_device:chr_file rw_file_perms;
|
allow domain qemu_device:chr_file rw_file_perms;
|
||||||
|
|
||||||
|
get_prop(domain, qemu_prop)
|
||||||
|
@@ -13,6 +13,8 @@ allow goldfish_setup toolbox_exec:file rx_file_perms;
|
|||||||
allow goldfish_setup self:capability { net_admin net_raw };
|
allow goldfish_setup self:capability { net_admin net_raw };
|
||||||
allow goldfish_setup self:udp_socket create_socket_perms;
|
allow goldfish_setup self:udp_socket create_socket_perms;
|
||||||
|
|
||||||
|
net_domain(goldfish_setup)
|
||||||
|
|
||||||
# Set net.eth0.dns*, debug.sf.nobootanimation
|
# Set net.eth0.dns*, debug.sf.nobootanimation
|
||||||
set_prop(goldfish_setup, system_prop)
|
set_prop(goldfish_setup, system_prop)
|
||||||
set_prop(goldfish_setup, debug_prop)
|
set_prop(goldfish_setup, debug_prop)
|
||||||
|
1
target/board/generic/sepolicy/netd.te
Normal file
1
target/board/generic/sepolicy/netd.te
Normal file
@@ -0,0 +1 @@
|
|||||||
|
dontaudit netd self:capability sys_module;
|
Reference in New Issue
Block a user