Skip to content
Snippets Groups Projects
  • Alex Klyubin's avatar
    0052bc69
    Further restrict access to Binder services from vendor · 0052bc69
    Alex Klyubin authored
    This tightens neverallows for looking up Binder servicemanager
    services from vendor components. In particular, vendor components,
    other than apps, are not permitted to look up any Binder services.
    Vendor apps are permitted to look up only stable public API services
    which is exactly what non-vendor apps are permitted to use as well.
    If we permitted vendor apps to use non-stable/hidden Binder services,
    they might break when core components get updated without updating
    vendor components.
    
    Test: mmm system/sepolicy
    Bug: 35870313
    
    Change-Id: I47d40d5d42cf4205d9e4e5e5f9d0794104efc28f
    0052bc69
    History
    Further restrict access to Binder services from vendor
    Alex Klyubin authored
    This tightens neverallows for looking up Binder servicemanager
    services from vendor components. In particular, vendor components,
    other than apps, are not permitted to look up any Binder services.
    Vendor apps are permitted to look up only stable public API services
    which is exactly what non-vendor apps are permitted to use as well.
    If we permitted vendor apps to use non-stable/hidden Binder services,
    they might break when core components get updated without updating
    vendor components.
    
    Test: mmm system/sepolicy
    Bug: 35870313
    
    Change-Id: I47d40d5d42cf4205d9e4e5e5f9d0794104efc28f