Skip to content
Permalink
Browse files

sepolicy: Allow map for untrusted_app -> su_exec.

Change-Id: I424a7cf76a74e25faf523dd84c687549b3c50b17
  • Loading branch information...
Heiher
Heiher committed Sep 6, 2019
1 parent a09f4a8 commit 2c523098d3a5a9a4e910ccfd8bbb0e5d72d835b3
Showing with 1 addition and 1 deletion.
  1. +1 −1 common/private/su.te
@@ -56,7 +56,7 @@ userdebug_or_eng(`
# typealias shell alias suclient;
# domain_auto_trans(untrusted_app, su_exec, suclient)

allow untrusted_app_all su_exec:file { execute_no_trans getattr open read execute };
allow untrusted_app_all su_exec:file { execute_no_trans getattr open read execute map };
allow untrusted_app_all sudaemon:unix_stream_socket { connectto read write setopt ioctl };
allow untrusted_app_all superuser_device:dir { r_dir_perms };
allow untrusted_app_all superuser_device:sock_file { write };

0 comments on commit 2c52309

Please sign in to comment.
You can’t perform that action at this time.