Skip to content
Snippets Groups Projects
Commit 01ec72ec authored by Nick Kralevich's avatar Nick Kralevich Committed by Android Git Automerger
Browse files

am 137e07f1: am f2c4e128: neverallow service_manager / service_manager_type

* commit '137e07f1':
  neverallow service_manager / service_manager_type
parents 01c80f2c 137e07f1
Branches
Tags
No related merge requests found
......@@ -493,3 +493,9 @@ neverallow {
userdebug_or_eng(`-uncrypt')
-installd
} shell_data_file:lnk_file read;
# servicemanager is the only process which handles list request
neverallow domain ~servicemanager:service_manager list;
# only service_manager_types can be added to service_manager
neverallow domain ~service_manager_type:service_manager { add find };
......@@ -282,3 +282,7 @@ neverallow init app_data_file:lnk_file read;
# init should never execute a program without changing to another domain.
neverallow init { file_type fs_type }:file execute_no_trans;
# Init never adds or uses services via service_manager.
neverallow init service_manager_type:service_manager { add find };
neverallow init servicemanager:service_manager list;
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment