Move most of public/vold_prepare_subdirs.te to private
AIUI permissions should be in private unless they need to be public. Bug: 25861755 Test: Boot device, create and remove a user, observe logs Change-Id: I6c3521d50dab2d508fce4b614d51e163e7c8f3da
This commit is contained in:
parent
621c24cbab
commit
5850a2ae6b
@ -1,3 +1,15 @@
|
||||
domain_auto_trans(vold, vold_prepare_subdirs_exec, vold_prepare_subdirs)
|
||||
|
||||
allow vold_prepare_subdirs system_file:file execute_no_trans;
|
||||
allow vold_prepare_subdirs shell_exec:file rx_file_perms;
|
||||
allow vold_prepare_subdirs toolbox_exec:file rx_file_perms;
|
||||
allow vold_prepare_subdirs devpts:chr_file rw_file_perms;
|
||||
allow vold_prepare_subdirs vold:fd use;
|
||||
allow vold_prepare_subdirs vold:fifo_file { read write };
|
||||
allow vold_prepare_subdirs file_contexts_file:file r_file_perms;
|
||||
allow vold_prepare_subdirs self:capability dac_override;
|
||||
allow vold_prepare_subdirs self:process setfscreate;
|
||||
allow vold_prepare_subdirs system_data_file:dir { open read write add_name remove_name };
|
||||
allow vold_prepare_subdirs vold_data_file:dir { create open read write search getattr setattr remove_name rmdir };
|
||||
allow vold_prepare_subdirs vold_data_file:file { getattr unlink };
|
||||
allow vold_prepare_subdirs storaged_data_file:dir create_dir_perms;
|
||||
|
@ -4,16 +4,3 @@ type vold_prepare_subdirs, domain;
|
||||
type vold_prepare_subdirs_exec, exec_type, file_type;
|
||||
|
||||
typeattribute vold_prepare_subdirs coredomain;
|
||||
|
||||
allow vold_prepare_subdirs system_file:file execute_no_trans;
|
||||
allow vold_prepare_subdirs shell_exec:file rx_file_perms;
|
||||
allow vold_prepare_subdirs toolbox_exec:file rx_file_perms;
|
||||
allow vold_prepare_subdirs devpts:chr_file rw_file_perms;
|
||||
allow vold_prepare_subdirs vold:fd use;
|
||||
allow vold_prepare_subdirs vold:fifo_file { read write };
|
||||
allow vold_prepare_subdirs file_contexts_file:file r_file_perms;
|
||||
allow vold_prepare_subdirs self:capability dac_override;
|
||||
allow vold_prepare_subdirs self:process setfscreate;
|
||||
allow vold_prepare_subdirs system_data_file:dir { open read write add_name remove_name };
|
||||
allow vold_prepare_subdirs vold_data_file:dir { create open read write search getattr setattr remove_name rmdir };
|
||||
allow vold_prepare_subdirs vold_data_file:file { getattr unlink };
|
||||
|
Loading…
Reference in New Issue
Block a user