Skip to content
Snippets Groups Projects
  • Stephen Smalley's avatar
    74ba8c86
    run-as policy fixes. · 74ba8c86
    Stephen Smalley authored
    - Remove dac_read_search as it is no longer required by run-as.
    - Introduce a separate type for /dev/tty so that we can allow use of own tty for
    for a run-as shell without allowing access to other /dev/tty[0-9]* nodes.
    - Allow sigchld notifications for death of run-as and its descendants by adbd.
    - Drop redundant rules for executing shell or system commands from untrusted_app;
    now covered by rules in app.te.
    
    Change-Id: Ic3bf7bee9eeabf9ad4a20f61fbb142a64bb37c6c
    74ba8c86
    History
    run-as policy fixes.
    Stephen Smalley authored
    - Remove dac_read_search as it is no longer required by run-as.
    - Introduce a separate type for /dev/tty so that we can allow use of own tty for
    for a run-as shell without allowing access to other /dev/tty[0-9]* nodes.
    - Allow sigchld notifications for death of run-as and its descendants by adbd.
    - Drop redundant rules for executing shell or system commands from untrusted_app;
    now covered by rules in app.te.
    
    Change-Id: Ic3bf7bee9eeabf9ad4a20f61fbb142a64bb37c6c