-
- Downloads
Strip file execute permissions from unconfined domains.
Exclude execute from the rules allowing access to files,
and only add it back for the rootfs and files labeled
with system_file (/system, /vendor) or one of the types in exec_type
(files under /system that cause domain transitions).
Change-Id: Ic72d76dc92e79bcc75a38398425af3bb1274a009
Signed-off-by:
Stephen Smalley <sds@tycho.nsa.gov>
Please register or sign in to comment