Skip to content
Snippets Groups Projects
  • Nick Kralevich's avatar
    5a570a4b
    Remove property read access for non-core properties · 5a570a4b
    Nick Kralevich authored
    Instead of allowing global read access to all properties,
    only allow read access to the properties which are part of
    core SELinux policy. Device-specific policies are no longer
    readable by default and need to be granted in device-specific
    policy.
    
    Grant read-access to any property where the person has write
    access. In most cases, anyone who wants to write a property
    needs read access to that property.
    
    Change-Id: I2bd24583067b79f31b3bb0940b4c07fc33d09918
    5a570a4b
    History
    Remove property read access for non-core properties
    Nick Kralevich authored
    Instead of allowing global read access to all properties,
    only allow read access to the properties which are part of
    core SELinux policy. Device-specific policies are no longer
    readable by default and need to be granted in device-specific
    policy.
    
    Grant read-access to any property where the person has write
    access. In most cases, anyone who wants to write a property
    needs read access to that property.
    
    Change-Id: I2bd24583067b79f31b3bb0940b4c07fc33d09918