Skip to content
Snippets Groups Projects
  • Nick Kralevich's avatar
    5207ca6a
    Enforce assumptions around metadata_block_device · 5207ca6a
    Nick Kralevich authored
    Add a compile time assertion that only authorized SELinux domains are
    allowed to touch the metadata_block_device. This domain may be wiped at
    will, and we want to ensure that we're not inadvertently destroying
    other people's data.
    
    Test: policy compiles.
    Change-Id: I9854b527c3d83e17f717d6cc8a1c6b50e0e373b6
    5207ca6a
    History
    Enforce assumptions around metadata_block_device
    Nick Kralevich authored
    Add a compile time assertion that only authorized SELinux domains are
    allowed to touch the metadata_block_device. This domain may be wiped at
    will, and we want to ensure that we're not inadvertently destroying
    other people's data.
    
    Test: policy compiles.
    Change-Id: I9854b527c3d83e17f717d6cc8a1c6b50e0e373b6