Files
device_google_walleye/sepolicy/kernel.te
Max Bires c60743aef5 Adding allows to init.te and kernel.te to address boot logs.
Allows take care of following denials:
denied { create } for pid=6 comm="kworker/u16:0"
scontext=u:r:kernel:s0 tcontext=u:r:kernel:s0 tclass=socket

denied  { mounton } for  pid=1 comm="init" path="/persist" dev="sda20"
ino=44 scontext=u:r:init:s0 tcontext=u:object_r:persist_file:s0
tclass=dir

Bug: 34784662
Test: The above denials no longer appear in bootup logs
Change-Id: I1a0db919938e4d56d60e07dad65db064a5f38d45
2017-02-07 14:56:31 -08:00

5 lines
80 B
Plaintext

# for diag over socket
userdebug_or_eng(`
allow kernel self:socket create;
')