diff --git a/public/domain.te b/public/domain.te index 3ed451a155e438b951b00c59ec8a016e25c8eea6..3f8eb66322aaa306c1977814f8105827bbe22947 100644 --- a/public/domain.te +++ b/public/domain.te @@ -451,11 +451,11 @@ full_treble_only(` ## # On full TREBLE devices core android components and vendor components may - # not directly access each other's data types. All communication must occur + # not directly access each other data types. All communication must occur # over HW binder. Open file descriptors may be passed and read/write/stat # operations my be performed on those FDs. Disallow all other operations. # - # do not allow vendor component access to coredomains' data types + # do not allow vendor component access to coredomains data types neverallow { domain -coredomain @@ -464,7 +464,7 @@ full_treble_only(` } core_data_file_type:{ file_class_set } ~{ append getattr ioctl read write }; - # do not allow vendor component access to coredomains' data directories. + # do not allow vendor component access to coredomains data directories. # /data has the system_data_file type. Allow all domains to have dir # search permissions which allows path traversal. neverallow {