Skip to content
Snippets Groups Projects
Commit 853ffaad authored by Stephen Smalley's avatar Stephen Smalley Committed by Nick Kralevich
Browse files

Deduplicate neverallow rules on selinuxfs operations.


We already have neverallow rules for all domains about
loading policy, setting enforcing mode, and setting
checkreqprot, so we can drop redundant ones from netd and appdomain.
Add neverallow rules to domain.te for setbool and setsecparam
and exclude them from unconfined to allow fully eliminating
separate neverallow rules on the :security class from anything
other than domain.te.

Change-Id: I0122e23ccb2b243f4c5376893e0c894f01f548fc
Signed-off-by: default avatarStephen Smalley <sds@tycho.nsa.gov>
parent 3696da6e
No related branches found
No related tags found
No related merge requests found
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment