Skip to content
Snippets Groups Projects
  • Nick Kralevich's avatar
    9a19885c
    remove "self:process ptrace" from domain, netd neverallow rules · 9a19885c
    Nick Kralevich authored
    Remove "self:process ptrace" from all SELinux enforced domains.
    In general, a process should never need to ptrace itself.
    We can add this back to more narrowly scoped domains as needed.
    
    Add a bunch of neverallow assertions to netd.te, to verify that netd
    never gets unexpected capabilities.
    
    Change-Id: Ie862dc95bec84068536bb64705667e36210c5f4e
    9a19885c
    History
    remove "self:process ptrace" from domain, netd neverallow rules
    Nick Kralevich authored
    Remove "self:process ptrace" from all SELinux enforced domains.
    In general, a process should never need to ptrace itself.
    We can add this back to more narrowly scoped domains as needed.
    
    Add a bunch of neverallow assertions to netd.te, to verify that netd
    never gets unexpected capabilities.
    
    Change-Id: Ie862dc95bec84068536bb64705667e36210c5f4e