Skip to content
Snippets Groups Projects
Commit 5487ca00 authored by Stephen Smalley's avatar Stephen Smalley
Browse files

Remove several superuser capabilities from unconfined domains.


Remove sys_ptrace and add a neverallow for it.
Remove sys_rawio and mknod, explicitly allow to kernel, init, and recovery,
and add a neverallow for them.
Remove sys_module.  It can be added back where appropriate in device
policy if using a modular kernel.  No neverallow since it is device
specific.

Change-Id: I1a7971db8d247fd53a8f9392de9e46250e91f89b
Signed-off-by: default avatarStephen Smalley <sds@tycho.nsa.gov>
parent 3db328fd
No related branches found
No related tags found
Loading
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment