Skip to content
Snippets Groups Projects
Commit 25e01176 authored by Nick Kralevich's avatar Nick Kralevich Committed by Android Git Automerger
Browse files

am bf65c7ef: mediaserver: remove /system/bin/toolbox exec access

* commit 'bf65c7ef':
  mediaserver: remove /system/bin/toolbox exec access
parents 4d526d86 bf65c7ef
No related branches found
No related tags found
No related merge requests found
......@@ -110,8 +110,8 @@ allow domain system_file:file execute;
allow domain system_file:lnk_file r_file_perms;
# Run toolbox.
# Kernel and init never run anything without changing domains.
allow { domain -kernel -init } toolbox_exec:file rx_file_perms;
# Kernel, init, and mediaserver never run anything without changing domains.
allow { domain -kernel -init -mediaserver } toolbox_exec:file rx_file_perms;
# Read files already opened under /data.
allow domain system_data_file:dir { search getattr };
......
......@@ -106,3 +106,11 @@ allow mediaserver drmserver:drmservice {
finalizeDecryptUnit
pread
};
###
### neverallow rules
###
# mediaserver should never execute any executable without a
# domain transition
neverallow mediaserver { file_type fs_type }:file execute_no_trans;
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment