Skip to content
Snippets Groups Projects
  • Stephen Smalley's avatar
    dd053a9b
    Define types for userdata and cache block devices. · dd053a9b
    Stephen Smalley authored
    
    Introduce separate types for the userdata and cache block
    devices so that we can assign them and allow access to them
    in device-specific policy without allowing access to any other
    block device (e.g. system).  These types will only be used if
    assigned to device node paths in the device-specific file_contexts
    configuration.  Otherwise, this change will have no impact - the
    userdata and cache block devices will continue to default to block_device
    type.
    
    To avoid breakage when these new types are assigned to the userdata
    block device, allow access by vold and uncrypt, but auditallow
    these accesses to confirm that these are required.
    
    Change-Id: I99d24f06506f51ebf1d186d9c393b3cad60e98d7
    Signed-off-by: default avatarStephen Smalley <sds@tycho.nsa.gov>
    dd053a9b
    History
    Define types for userdata and cache block devices.
    Stephen Smalley authored
    
    Introduce separate types for the userdata and cache block
    devices so that we can assign them and allow access to them
    in device-specific policy without allowing access to any other
    block device (e.g. system).  These types will only be used if
    assigned to device node paths in the device-specific file_contexts
    configuration.  Otherwise, this change will have no impact - the
    userdata and cache block devices will continue to default to block_device
    type.
    
    To avoid breakage when these new types are assigned to the userdata
    block device, allow access by vold and uncrypt, but auditallow
    these accesses to confirm that these are required.
    
    Change-Id: I99d24f06506f51ebf1d186d9c393b3cad60e98d7
    Signed-off-by: default avatarStephen Smalley <sds@tycho.nsa.gov>