kernel: Use CONFIG_KSU_MANUAL_SU to protect MANUAL_SU

This commit is contained in:
ShirkNeko
2025-11-05 16:17:54 +08:00
parent 557e7f8153
commit 994fdfddf2
3 changed files with 15 additions and 5 deletions

View File

@@ -127,7 +127,9 @@ void apply_kernelsu_rules()
ksu_allow(db, "system_server", KERNEL_SU_DOMAIN, "process", "getpgid");
ksu_allow(db, "system_server", KERNEL_SU_DOMAIN, "process", "sigkill");
#ifdef CONFIG_KSU_MANUAL_SU
ksu_allow(db, "shell", "shell", "netlink_connector_socket", ALL);
#endif
// https://android-review.googlesource.com/c/platform/system/logging/+/3725346
ksu_dontaudit(db, "untrusted_app", KERNEL_SU_DOMAIN, "dir", "getattr");