Skip to content
Snippets Groups Projects
Select Git revision
  • android-7.1.2_r28_klist
  • master default protected
  • pie-cts-release
  • pie-vts-release
  • pie-cts-dev
  • oreo-mr1-iot-release
  • sdk-release
  • oreo-m6-s4-release
  • oreo-m4-s12-release
  • pie-release
  • pie-r2-release
  • pie-r2-s1-release
  • oreo-vts-release
  • oreo-cts-release
  • oreo-dev
  • oreo-mr1-dev
  • pie-gsi
  • pie-platform-release
  • pie-dev
  • oreo-cts-dev
  • android-o-mr1-iot-release-1.0.4
  • android-9.0.0_r8
  • android-9.0.0_r7
  • android-9.0.0_r6
  • android-9.0.0_r5
  • android-8.1.0_r46
  • android-8.1.0_r45
  • android-n-iot-release-smart-display-r2
  • android-vts-8.1_r5
  • android-cts-8.1_r8
  • android-cts-8.0_r12
  • android-cts-7.1_r20
  • android-cts-7.0_r24
  • android-o-mr1-iot-release-1.0.3
  • android-cts-9.0_r1
  • android-8.1.0_r43
  • android-8.1.0_r42
  • android-n-iot-release-smart-display
  • android-p-preview-5
  • android-9.0.0_r3
40 results

init.te

  • Max Bires's avatar
    3171829a
    Removing init and ueventd access to generic char files · 3171829a
    Max Bires authored
    There are many character files that are unreachable to all processes
    under selinux policies. Ueventd and init were the only two domains that
    had access to these generic character files, but auditing proved there
    was no use for that access. In light of this, access is being completely
    revoked so that the device nodes can be removed, and a neverallow is
    being audited to prevent future regressions.
    
    Test: The device boots
    Bug: 33347297
    Change-Id: If050693e5e5a65533f3d909382e40f9c6b85f61c
    3171829a
    History
    Removing init and ueventd access to generic char files
    Max Bires authored
    There are many character files that are unreachable to all processes
    under selinux policies. Ueventd and init were the only two domains that
    had access to these generic character files, but auditing proved there
    was no use for that access. In light of this, access is being completely
    revoked so that the device nodes can be removed, and a neverallow is
    being audited to prevent future regressions.
    
    Test: The device boots
    Bug: 33347297
    Change-Id: If050693e5e5a65533f3d909382e40f9c6b85f61c