Merge "Don't audit storageproxyd unlabeled access" am: fbf92e2ada

Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2007441

Change-Id: I7b9186af0cb135241e23504fa9d6f7c3d6718c7c
This commit is contained in:
Tri Vo 2022-03-04 18:06:53 +00:00 committed by Automerger Merge Worker
commit 22f2ffcbee

View file

@ -15,3 +15,7 @@ allow tee self:capability { setgid setuid };
# Allow storageproxyd access to gsi_public_metadata_file
read_fstab(tee)
# storageproxyd starts before /data is mounted. It handles /data not being there
# gracefully. However, attempts to access /data trigger a denial.
dontaudit tee unlabeled:dir { search };