Merge "Add permissions for chattr"

This commit is contained in:
Daniel Rosenberg 2020-01-30 03:33:21 +00:00 committed by Gerrit Code Review
commit 7b6cd1e43e

View File

@ -27,3 +27,7 @@ neverallow toolbox { file_type fs_type -toolbox_exec}:file entrypoint;
allow toolbox system_data_root_file:dir { remove_name write };
allow toolbox system_data_file:dir { rmdir rw_dir_perms };
allow toolbox system_data_file:file { getattr unlink };
# chattr +F /data/media in init
allow toolbox media_rw_data_file:dir { r_dir_perms };
allowxperm toolbox media_rw_data_file:dir ioctl { FS_IOC_SETFLAGS FS_IOC_GETFLAGS };