Skip to content
Snippets Groups Projects
Commit 88ae5595 authored by Stephen Smalley's avatar Stephen Smalley
Browse files

Drop SELinux management rules from AOSP.


As AOSP does not support the device admin API or the older
SEManager system app, just drop the allow rules associated with
permitting SELinux management via device admin or a system app.

Change-Id: Icdf40c9e6d343b19c156e4c7aea4cfb8c5f234ad
Signed-off-by: default avatarStephen Smalley <sds@tycho.nsa.gov>
parent cebe6a65
No related branches found
No related tags found
No related merge requests found
...@@ -30,22 +30,6 @@ selinux_getenforce(system_app) ...@@ -30,22 +30,6 @@ selinux_getenforce(system_app)
# Settings app reads sdcard for storage stats # Settings app reads sdcard for storage stats
allow system_app sdcard_type:dir r_dir_perms; allow system_app sdcard_type:dir r_dir_perms;
bool manage_selinux true;
if (manage_selinux) {
selinux_manage_policy(system)
selinux_manage_policy(system_app)
access_kmsg(system)
access_kmsg(system_app)
}
bool manage_mac true;
if (manage_mac) {
mmac_manage_policy(system)
mmac_manage_policy(system_app)
access_logcat(system)
access_logcat(system_app)
}
# #
# System Server aka system_server spawned by zygote. # System Server aka system_server spawned by zygote.
# Most of the framework services run in this process. # Most of the framework services run in this process.
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment