Skip to content
Snippets Groups Projects
Commit 631a5a8e authored by Stephen Smalley's avatar Stephen Smalley
Browse files

Remove app_data_file access from unconfineddomain.


Require app_data_file access to be explicitly allowed to
each domain.  We especially do not want to allow
app_data_file:lnk_file read to any privileged domain.
But removing app_data_file access in general can be useful
in protecting app data from rogue daemons.

Change-Id: I46240562bce76579e108495ab15833e143841ad8
Signed-off-by: default avatarStephen Smalley <sds@tycho.nsa.gov>
parent 04b8a75c
No related branches found
No related tags found
Loading
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment