Skip to content
Snippets Groups Projects
  • Alex Klyubin's avatar
    fa57d415
    Tighten isolated_app -> *Binder policy · fa57d415
    Alex Klyubin authored
    * isolated_app is no longer permitted to access /dev/hwbinder -- this
      was granted by mistake.
    * There are now neverallows which enforce that isolated_app can't
      access HwBinder and VendorBinder.
    * There are now neverallows which enforce that isolated_app can't add
      Binder and VendorBinder services to servicemanager and
      vndservicemanager.
    
    Test: mmm system/sepolicy
    Bug: 34454312
    Change-Id: I8ba90a0dcb6a9fccd8f50c78cbd2409381376f7a
    fa57d415
    History
    Tighten isolated_app -> *Binder policy
    Alex Klyubin authored
    * isolated_app is no longer permitted to access /dev/hwbinder -- this
      was granted by mistake.
    * There are now neverallows which enforce that isolated_app can't
      access HwBinder and VendorBinder.
    * There are now neverallows which enforce that isolated_app can't add
      Binder and VendorBinder services to servicemanager and
      vndservicemanager.
    
    Test: mmm system/sepolicy
    Bug: 34454312
    Change-Id: I8ba90a0dcb6a9fccd8f50c78cbd2409381376f7a