Skip to content
Snippets Groups Projects
Commit 14742b0f authored by William Roberts's avatar William Roberts Committed by android-build-merger
Browse files

Merge "domain: neverallow on setfcap"

am: e112faea

Change-Id: I57d5ed15ae69613145a9ef4efc9e16ec72ad420b
parents 3ad4428c e112faea
No related branches found
No related tags found
No related merge requests found
......@@ -653,3 +653,10 @@ neverallow {
# Do not allow kernel module loading except from system,
# vendor, and boot partitions.
neverallow * ~{ system_file rootfs }:system module_load;
# Only allow filesystem caps to be set at build time or
# during upgrade by recovery.
neverallow {
domain
-recovery
} self:capability setfcap;
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment