android avc neverallow定义查找

在修改avc后,有时候编译会报错neverallow。这个具体是在什么地方定义的呢

目录:
system/sepolicy/private/
domain.te

# Limit ability to ptrace or read sensitive /proc/pid files of processes
# with other UIDs to these whitelisted domains.
neverallow {
  domain
  -vold
  userdebug_or_eng(`-llkd')
  -dumpstate
  userdebug_or_eng(`-incidentd')
  -storaged
  -system_server
  userdebug_or_eng(`-perfprofd')
} self:global_capability_class_set sys_ptrace;
....

coredomain.te

neverallow {
    coredomain

    # for chowning
    -init

    # generic access to sysfs_type
    -ueventd
    -vold
    # meig:jicong.wang add for cit
    -system_app
} sysfs_leds:file *;
')

如果修改了上面两个文件
prebuilts/api 也要响应的修改。不管会报错

你可能感兴趣的:(Android)