Skip to content
Snippets Groups Projects
  • Stephen Smalley's avatar
    f853715d
    Remove setting /proc/self/attr/* from unconfined. · f853715d
    Stephen Smalley authored
    
    Change I6a2fb1279318625a80f3ea8e3f0932bdbe6df676 removed
    these permissions from domain.te and added them to specific domains
    as required.  Remove the permissions from unconfineddomain as well
    so that they are only allowed where explicitly allowed.  The earlier
    change already added the necessary permissions to init, kernel,
    and recovery so we do not need to add them here.
    
    Change-Id: Ifeb5438532a7525e64328e1c54b436e9b6f7fd3b
    Signed-off-by: default avatarStephen Smalley <sds@tycho.nsa.gov>
    f853715d
    History
    Remove setting /proc/self/attr/* from unconfined.
    Stephen Smalley authored
    
    Change I6a2fb1279318625a80f3ea8e3f0932bdbe6df676 removed
    these permissions from domain.te and added them to specific domains
    as required.  Remove the permissions from unconfineddomain as well
    so that they are only allowed where explicitly allowed.  The earlier
    change already added the necessary permissions to init, kernel,
    and recovery so we do not need to add them here.
    
    Change-Id: Ifeb5438532a7525e64328e1c54b436e9b6f7fd3b
    Signed-off-by: default avatarStephen Smalley <sds@tycho.nsa.gov>