reject mnt_vendor_file access in user ROM

Bug: 224429437
Test: android.security.cts.SELinuxHostTest#testNoBugreportDenials
Change-Id: I318f11866f7b9c6cc0b7ecf151f789f35ab290cd
This commit is contained in:
Adam Shih 2022-03-16 14:08:09 +08:00
parent 38c2803c54
commit bedd866505

View file

@ -111,6 +111,7 @@ userdebug_or_eng(`
allow hal_dumpstate_default vendor_dri_debugfs:file r_file_perms;
')
dontaudit hal_dumpstate_default mnt_vendor_file:dir search;
dontaudit hal_dumpstate_default vendor_dri_debugfs:dir r_dir_perms;
dontaudit hal_dumpstate_default vendor_dri_debugfs:file r_file_perms;
dontaudit hal_dumpstate_default debugfs:dir r_dir_perms;