Anonymous committed 22881eb

allow lmkd to kill processes.

The previous patch wasn't sufficient. Allow the kill signal.

Addresses the following denial:

<5>[ 775.819223] type=1400 audit(1393978653.489:18): avc: denied { sigkill } for pid=118 comm="lmkd" scontext=u:r:lmkd:s0 tcontext=u:r:untrusted_app:s0 tclass=process

Bug: 13084787
Change-Id: I6af1ed4343b590049809a59e4f2797f6049f12e4

Comments (0)

Files changed (1)

 ## Writes to /sys/module/lowmemorykiller/parameters/minfree
 allow lmkd sysfs_lowmemorykiller:file w_file_perms;
+# Send kill signals
+allow lmkd appdomain:process sigkill;