selinux: rfs_access: fix tftp_server denials when operating on tombstones file am: a82169492c

am: 4784c2a4bc

Change-Id: Ia68023c6a8cadf0ef76753ea7c15c73d4a04b3fd
This commit is contained in:
SalmaxChang
2018-12-21 23:46:06 -08:00
committed by android-build-merger
3 changed files with 8 additions and 0 deletions

View File

@@ -79,6 +79,9 @@ type sensors_vendor_data_file, file_type, data_file_type;
type audio_vendor_data_file, file_type, data_file_type;
type mediadrm_vendor_data_file, file_type, data_file_type;
# Tombstone vendor data
type tombstone_vendor_data_file, file_type, data_file_type;
#diag sysfs files
type sysfs_diag, fs_type, sysfs_type;

View File

@@ -256,6 +256,7 @@
/data/vendor/sensors(/.*)? u:object_r:sensors_vendor_data_file:s0
/data/vendor/audio(/.*)? u:object_r:audio_vendor_data_file:s0
/data/vendor/mediadrm(/.*)? u:object_r:mediadrm_vendor_data_file:s0
/data/vendor/tombstones(/.*)? u:object_r:tombstone_vendor_data_file:s0
/data/vendor_ce/[0-9]+/ramoops(/.*)? u:object_r:ramoops_vendor_data_file:s0
# /

View File

@@ -16,3 +16,7 @@ allow rfs_access persist_rfs_file:dir create_dir_perms;
allow rfs_access persist_rfs_file:file create_file_perms;
allow rfs_access self:socket create_socket_perms_no_ioctl;
# For ramdump entries in /data/vendor/tombstones
allow rfs_access tombstone_vendor_data_file:dir create_dir_perms;
allow rfs_access tombstone_vendor_data_file:file create_file_perms;