Skip to content
Snippets Groups Projects
Select Git revision
  • android-7.1.2_r28_klist
  • master default protected
  • pie-cts-release
  • pie-vts-release
  • pie-cts-dev
  • oreo-mr1-iot-release
  • sdk-release
  • oreo-m6-s4-release
  • oreo-m4-s12-release
  • pie-release
  • pie-r2-release
  • pie-r2-s1-release
  • oreo-vts-release
  • oreo-cts-release
  • oreo-dev
  • oreo-mr1-dev
  • pie-gsi
  • pie-platform-release
  • pie-dev
  • oreo-cts-dev
  • android-o-mr1-iot-release-1.0.4
  • android-9.0.0_r8
  • android-9.0.0_r7
  • android-9.0.0_r6
  • android-9.0.0_r5
  • android-8.1.0_r46
  • android-8.1.0_r45
  • android-n-iot-release-smart-display-r2
  • android-vts-8.1_r5
  • android-cts-8.1_r8
  • android-cts-8.0_r12
  • android-cts-7.1_r20
  • android-cts-7.0_r24
  • android-o-mr1-iot-release-1.0.3
  • android-cts-9.0_r1
  • android-8.1.0_r43
  • android-8.1.0_r42
  • android-n-iot-release-smart-display
  • android-p-preview-5
  • android-9.0.0_r3
40 results

kernel.te

Blame
    • Nick Kralevich's avatar
      02cfce49
      kernel.te: tighten entrypoint / execute_no_trans neverallow · 02cfce49
      Nick Kralevich authored
      The kernel domain exists solely on boot, and is used by kernel threads.
      Because of the way the system starts, there is never an entrypoint for
      that domain, not even a file on rootfs. So tighten up the neverallow
      restriction.
      
      Remove an obsolete comment. The *.rc files no longer have a setcon
      statement, and the transition from the kernel domain to init occurs
      because init re-execs itself. The statement no longer applies.
      
      Test: bullhead policy compiles.
      Change-Id: Ibe75f3d25804453507dbb05c7a07bba1d37a1c7b
      02cfce49
      History
      kernel.te: tighten entrypoint / execute_no_trans neverallow
      Nick Kralevich authored
      The kernel domain exists solely on boot, and is used by kernel threads.
      Because of the way the system starts, there is never an entrypoint for
      that domain, not even a file on rootfs. So tighten up the neverallow
      restriction.
      
      Remove an obsolete comment. The *.rc files no longer have a setcon
      statement, and the transition from the kernel domain to init occurs
      because init re-execs itself. The statement no longer applies.
      
      Test: bullhead policy compiles.
      Change-Id: Ibe75f3d25804453507dbb05c7a07bba1d37a1c7b