Skip to content
Snippets Groups Projects
  • Nick Kralevich's avatar
    abae8a9b
    Revisit kernel setenforce · abae8a9b
    Nick Kralevich authored
    Kernel userspace helpers may be spawned running in the kernel
    SELinux domain. Those userspace helpers shouldn't be able to turn
    SELinux off.
    
    This change revisits the discussion in
    https://android-review.googlesource.com/#/c/71184/
    
    At the time, we were debating whether or not to have an allow rule,
    or a dontaudit rule. Both have the same effect, as at the time we
    switch to enforcing mode, the kernel is in permissive and the operation
    will be allowed.
    
    Change-Id: If335a5cf619125806c700780fcf91f8602083824
    abae8a9b
    History
    Revisit kernel setenforce
    Nick Kralevich authored
    Kernel userspace helpers may be spawned running in the kernel
    SELinux domain. Those userspace helpers shouldn't be able to turn
    SELinux off.
    
    This change revisits the discussion in
    https://android-review.googlesource.com/#/c/71184/
    
    At the time, we were debating whether or not to have an allow rule,
    or a dontaudit rule. Both have the same effect, as at the time we
    switch to enforcing mode, the kernel is in permissive and the operation
    will be allowed.
    
    Change-Id: If335a5cf619125806c700780fcf91f8602083824