Skip to content
Snippets Groups Projects
Commit 712ca0a4 authored by Stephen Smalley's avatar Stephen Smalley
Browse files

Confine shell domain in -user builds only.


Confine the domain for an adb shell in -user builds only.
The shell domain in non-user builds is left permissive.
init_shell (shell spawned by init, e.g.  console service)
remains unconfined by this change.
Introduce a shelldomain attribute for rules common to all shell
domains, assign it to the shell types, and add shelldomain.te for
its rules.

Change-Id: I01ee2c7ef80b61a9db151abe182ef9af7623c461
Signed-off-by: default avatarStephen Smalley <sds@tycho.nsa.gov>
parent 09e6abd9
No related branches found
No related tags found
No related merge requests found
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment