Skip to content
Snippets Groups Projects
  • Nick Kralevich's avatar
    96b1c9ca
    neverallow debugfs access · 96b1c9ca
    Nick Kralevich authored
    Don't allow access to the generic debugfs label. Instead, force
    relabeling to a more specific type. system_server and dumpstate
    are excluded from this until I have time to fix them.
    
    Tighten up the neverallow rules for untrusted_app. It should never
    be reading any file on /sys/kernel/debug, regardless of the label.
    
    Change-Id: Ic7feff9ba3aca450f1e0b6f253f0b56c7918d0fa
    96b1c9ca
    History
    neverallow debugfs access
    Nick Kralevich authored
    Don't allow access to the generic debugfs label. Instead, force
    relabeling to a more specific type. system_server and dumpstate
    are excluded from this until I have time to fix them.
    
    Tighten up the neverallow rules for untrusted_app. It should never
    be reading any file on /sys/kernel/debug, regardless of the label.
    
    Change-Id: Ic7feff9ba3aca450f1e0b6f253f0b56c7918d0fa