DivestOS/Patches/LineageOS-14.1/android_system_sepolicy/0002-protected_files.patch
Tad bda848a0a1 Fixup 057bedb6
Sadly this means the option was never enabled :(
Note: these options are only available on 4.4+ kernels

Signed-off-by: Tad <tad@spotco.us>
2022-03-06 23:05:13 -05:00

29 lines
1.2 KiB
Diff

From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
From: Daniel Micay <danielmicay@gmail.com>
Date: Thu, 18 Jul 2019 21:21:40 -0400
Subject: [PATCH] label protected_{fifos,regular} as proc_security
This is needed for init to override the default values.
Signed-off-by: anupritaisno1 <www.anuprita804@gmail.com>
[tad@spotco.us]: added to older targets to match
Change-Id: I19be49956510d3e74f96b837ce7e8d33cff650c1
---
genfs_contexts | 2 ++
1 file changed, 2 insertions(+)
diff --git a/genfs_contexts b/genfs_contexts
index 31794a1e8..7597b4c6d 100644
--- a/genfs_contexts
+++ b/genfs_contexts
@@ -8,7 +8,9 @@ genfscon proc /net u:object_r:proc_net:s0
genfscon proc /net/xt_qtaguid/ctrl u:object_r:qtaguid_proc:s0
genfscon proc /cpuinfo u:object_r:proc_cpuinfo:s0
genfscon proc /sysrq-trigger u:object_r:proc_sysrq:s0
+genfscon proc /sys/fs/protected_fifos u:object_r:proc_security:s0
genfscon proc /sys/fs/protected_hardlinks u:object_r:proc_security:s0
+genfscon proc /sys/fs/protected_regular u:object_r:proc_security:s0
genfscon proc /sys/fs/protected_symlinks u:object_r:proc_security:s0
genfscon proc /sys/fs/suid_dumpable u:object_r:proc_security:s0
genfscon proc /sys/kernel/core_pattern u:object_r:usermodehelper:s0