diff --git a/domain.te b/domain.te index bb9b225bd73316526f8e67e1f88a520d2f693a43..9b2024b0347316efcb5c759dbf7ab74a216b6ebe 100644 --- a/domain.te +++ b/domain.te @@ -166,7 +166,7 @@ neverallow { } self:capability mknod; # Limit raw I/O to these whitelisted domains. -neverallow { domain -kernel -init -recovery -ueventd -watchdogd -healthd -vold -uncrypt -tee } self:capability sys_rawio; +neverallow { domain -kernel -init -recovery -ueventd -watchdogd -healthd -uncrypt -tee } self:capability sys_rawio; # No process can map low memory (< CONFIG_LSM_MMAP_MIN_ADDR). neverallow * self:memprotect mmap_zero;