Merge "Don't audit storageproxyd unlabeled access" am: fbf92e2ada am: 22f2ffcbee

Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2007441

Change-Id: Ie2af054a900f32cbde1352ba9f708e163f76d86c
This commit is contained in:
Tri Vo 2022-03-04 18:29:27 +00:00 committed by Automerger Merge Worker
commit a5ccc7efa8

View file

@ -15,3 +15,7 @@ allow tee self:capability { setgid setuid };
# Allow storageproxyd access to gsi_public_metadata_file
read_fstab(tee)
# storageproxyd starts before /data is mounted. It handles /data not being there
# gracefully. However, attempts to access /data trigger a denial.
dontaudit tee unlabeled:dir { search };