Skip to content
Snippets Groups Projects
Commit 393c8e94 authored by TreeHugger Robot's avatar TreeHugger Robot Committed by Android (Google) Code Review
Browse files

Merge "Do not allow untrusted apps any access to kernel configuration" into oc-dev

parents 8d567da2 2da9cfdf
No related branches found
No related tags found
No related merge requests found
......@@ -98,6 +98,9 @@ neverallow all_untrusted_apps anr_data_file:dir ~search;
# Create a more specific label if needed
neverallow all_untrusted_apps proc:file { no_rw_file_perms no_x_file_perms };
# Avoid all access to kernel configuration
neverallow all_untrusted_apps config_gz:file { no_rw_file_perms no_x_file_perms };
# Do not allow untrusted apps access to preloads data files
neverallow all_untrusted_apps preloads_data_file:file no_rw_file_perms;
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment