Remove obdm_app access to proc label.

Instead give obdm_app read access to /proc/stat.

Bug: 65643247
Test: can login to obdm app without selinux denials

Change-Id: I368c018f883610364cd026da68085935aefd69c1
This commit is contained in:
Tri Vo
2017-10-16 15:01:45 -07:00
parent e6334a7789
commit 036ef1ebc2

View File

@@ -3,7 +3,7 @@ type obdm_app, domain, coredomain;
app_domain(obdm_app)
net_domain(obdm_app)
r_dir_file(obdm_app, proc)
allow obdm_app proc_stat:file r_file_perms;
# talk to /dev/diag
allow obdm_app diag_device:chr_file rw_file_perms;