summaryrefslogtreecommitdiff
path: root/tools/aapt2/java/JavaClassGenerator.cpp
diff options
context:
space:
mode:
authorJeff Vander Stoep <jeffv@google.com>2020-04-23 10:12:56 +0200
committerJeff Vander Stoep <jeffv@google.com>2020-04-23 10:12:56 +0200
commit3c587db57d104354d92e41892327beb1b37ca88b (patch)
treecc3e639c1055ba8bd7b09a35f02317b862d32cca /tools/aapt2/java/JavaClassGenerator.cpp
parentbbb5a3c7f7f29224f62eeddc83388ad4932e8be1 (diff)
derive_sdk: run as nobody
Unfortunately, root is the default user/group for init-launched services. This can lead to processes unnecessarily requesting permissions like privileged capabilities. This service doesn't require any privileges so run it as AID_NOBODY. Addresses: avc: denied { sys_resource } for comm=\"derive_sdk\" capability=24 scontext=u:r:derive_sdk:s0 tcontext=u:r:derive_sdk:s0 tclass=capability permissive=0 Bug: 154711554 Test: m com.android.sdkext Test: boot && adb shell getprop | grep sdk_info Change-Id: Ibd4ad616901a9d5c402ba89d636d0238b0043afa
Diffstat (limited to 'tools/aapt2/java/JavaClassGenerator.cpp')
0 files changed, 0 insertions, 0 deletions