From 2cf7bb4e17ddfb1251be7cbe7e1da07df44f4e5f Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Andy=20=7C=20=E3=82=A2=E3=83=B3=E3=83=87=E3=82=A3?= Date: Wed, 6 Sep 2023 19:41:03 +0800 Subject: [PATCH] sm6375-common: sepolicy: Don't audit odrefresh to killing process 07-07 10:07:50.071 754 754 I auditd : type=1400 audit(0.0:9): avc: denied { kill } for comm="odrefresh" capability=5 scontext=u:r:odrefresh:s0 tcontext=u:r:odrefresh:s0 tclass=capability permissive=0 --- sepolicy/private/dontaudit.te | 1 + sepolicy/vendor/dontaudit.te | 2 +- 2 files changed, 2 insertions(+), 1 deletion(-) create mode 100644 sepolicy/private/dontaudit.te diff --git a/sepolicy/private/dontaudit.te b/sepolicy/private/dontaudit.te new file mode 100644 index 0000000..57c2eaf --- /dev/null +++ b/sepolicy/private/dontaudit.te @@ -0,0 +1 @@ +dontaudit odrefresh odrefresh:capability kill; diff --git a/sepolicy/vendor/dontaudit.te b/sepolicy/vendor/dontaudit.te index 7e55ad9..92f5e0a 100644 --- a/sepolicy/vendor/dontaudit.te +++ b/sepolicy/vendor/dontaudit.te @@ -5,4 +5,4 @@ dontaudit { # Apps are no longer allowed open access to /dev/ashmem, unless they # target API level < Q. -dontaudit untrusted_app ashmem_device:chr_file open; +dontaudit untrusted_app ashmem_device:chr_file open; \ No newline at end of file