Skip to content
Snippets Groups Projects
Commit 76f3fe33 authored by dcashman's avatar dcashman
Browse files

Add neverallow rule for set_context_mgr.

Change-Id: Ie7c2bf623dcfe246fa5e60b0775b6bb38869d8cb
parent 0be02b36
No related branches found
No related tags found
No related merge requests found
......@@ -329,3 +329,6 @@ neverallow { domain -recovery } system_block_device:blk_file write;
# No domains other than install_recovery or recovery can write to recovery.
neverallow { domain -install_recovery -recovery } recovery_block_device:blk_file write;
# Only servicemanager should be able to register with binder as the context manager
neverallow { domain -servicemanager } *:binder set_context_mgr;
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment