Skip to content
Snippets Groups Projects
  • Nick Kralevich's avatar
    cd905ec0
    Protect keystore's files. · cd905ec0
    Nick Kralevich authored
    Only keystore itself should be reading / writing it's files.
    Remove keystore file access from other SELinux domains, including
    unconfined. Add neverallow rules to protect against regressions.
    Allow init limited access to recurse into keystore's directory.
    
    Change-Id: I0bb5de7804f4314997c16fac18507933014bcadf
    cd905ec0
    History
    Protect keystore's files.
    Nick Kralevich authored
    Only keystore itself should be reading / writing it's files.
    Remove keystore file access from other SELinux domains, including
    unconfined. Add neverallow rules to protect against regressions.
    Allow init limited access to recurse into keystore's directory.
    
    Change-Id: I0bb5de7804f4314997c16fac18507933014bcadf