From fa7d97fa15700b62b01d0b7dd42fcaf12c57b9f5 Mon Sep 17 00:00:00 2001 From: Christopher Tate Date: Thu, 30 Jun 2016 12:21:57 -0700 Subject: [PATCH] Make sure SELinux labels are correct after move-to operations In some circumstances wallpaper-related files are moved into position, and must then take proper effect. Make sure that they have the correct SELinux labels afterwards to avoid preventing some valid accesses. Bug 29469965 Change-Id: I6d7c86be63d568fa0ad8841d109a7ff2149fdd54 --- .../android/server/wallpaper/WallpaperManagerService.java | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/services/core/java/com/android/server/wallpaper/WallpaperManagerService.java b/services/core/java/com/android/server/wallpaper/WallpaperManagerService.java index efd238201e7a6..8137c4ed3721f 100644 --- a/services/core/java/com/android/server/wallpaper/WallpaperManagerService.java +++ b/services/core/java/com/android/server/wallpaper/WallpaperManagerService.java @@ -229,10 +229,12 @@ public class WallpaperManagerService extends IWallpaperManager.Stub { if (moved && lockWallpaperChanged) { // We just migrated sys -> lock to preserve imagery for an impending - // new system-only wallpaper. Tell keyguard about it but that's it. + // new system-only wallpaper. Tell keyguard about it and make sure it + // has the right SELinux label. if (DEBUG) { Slog.i(TAG, "Sys -> lock MOVED_TO"); } + SELinux.restorecon(changedFile); notifyLockWallpaperChanged(); return; } @@ -254,9 +256,11 @@ public class WallpaperManagerService extends IWallpaperManager.Stub { if (moved) { // This is a restore, so generate the crop using any just-restored new // crop guidelines, making sure to preserve our local dimension hints. + // We also make sure to reapply the correct SELinux label. if (DEBUG) { Slog.v(TAG, "moved-to, therefore restore; reloading metadata"); } + SELinux.restorecon(changedFile); loadSettingsLocked(wallpaper.userId, true); } generateCrop(wallpaper);