Skip to content
Snippets Groups Projects
Commit 3fc0df76 authored by William Roberts's avatar William Roberts Committed by Android Git Automerger
Browse files

am a637b2f2: assert: Do not allow access to generic device:chr_file

* commit 'a637b2f2':
  assert: Do not allow access to generic device:chr_file
parents df80ebd9 a637b2f2
No related branches found
No related tags found
No related merge requests found
...@@ -201,9 +201,6 @@ neverallow { appdomain -unconfineddomain } self:capability2 *; ...@@ -201,9 +201,6 @@ neverallow { appdomain -unconfineddomain } self:capability2 *;
# Block device access. # Block device access.
neverallow { appdomain -unconfineddomain } dev_type:blk_file { read write }; neverallow { appdomain -unconfineddomain } dev_type:blk_file { read write };
# Access to any character device that is not specifically typed.
neverallow { appdomain -unconfineddomain } device:chr_file { read write };
# Access to any of the following character devices. # Access to any of the following character devices.
neverallow { appdomain -unconfineddomain } { neverallow { appdomain -unconfineddomain } {
audio_device audio_device
......
...@@ -187,3 +187,8 @@ neverallow domain init:binder call; ...@@ -187,3 +187,8 @@ neverallow domain init:binder call;
# Don't allow raw read/write/open access to block_device # Don't allow raw read/write/open access to block_device
# Rather force a relabel to a more specific type # Rather force a relabel to a more specific type
neverallow { domain -unconfineddomain -vold } block_device:blk_file { open read write }; neverallow { domain -unconfineddomain -vold } block_device:blk_file { open read write };
# Don't allow raw read/write/open access to generic devices.
# Rather force a relabel to a more specific type.
# ueventd is exempt from this, as its managing these devices.
neverallow { domain -unconfineddomain -ueventd } device:chr_file { open read write };
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment