Skip to content
Snippets Groups Projects
Commit 7028bdcc authored by William Roberts's avatar William Roberts Committed by William C Roberts
Browse files

neverallow: domain execute data_file_type


To help reduce code injection paths, a neverallow is placed
to prevent domain, sans untrusted_app and shell, execute
on data_file_type. A few data_file_type's are also exempt
from this rule as they label files that should be executable.

Additional constraints, on top of the above, are placed on domains
system_server and zygote. They can only execute data_file_type's
of type dalvikcache_data_file.

Change-Id: I15dafbce80ba2c85a03c23128eae4725703d5f02
Signed-off-by: default avatarWilliam Roberts <william.c.roberts@intel.com>
parent 99fe8df2
No related branches found
No related tags found
No related merge requests found
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment