Skip to content
Snippets Groups Projects
Commit 8daacf64 authored by Mark Salyzyn's avatar Mark Salyzyn
Browse files

init: lock down access to keychord_device

The out-of-tree keychord driver is only intended for use by init.

Test: build
Bug: 64114943
Bug: 78174219
Change-Id: I96a7fbcd9a54a38625063606f5c4ab6d40d701f6
parent ae0b835c
No related branches found
No related tags found
No related merge requests found
...@@ -363,6 +363,14 @@ neverallow { ...@@ -363,6 +363,14 @@ neverallow {
-system_server -system_server
-ueventd -ueventd
} hw_random_device:chr_file *; } hw_random_device:chr_file *;
# b/78174219 b/64114943
neverallow {
domain
-init
-shell # stat of /dev, getattr only
-vendor_init
-ueventd
} keychord_device:chr_file *;
# Ensure that all entrypoint executables are in exec_type or postinstall_file. # Ensure that all entrypoint executables are in exec_type or postinstall_file.
neverallow * { file_type -exec_type -postinstall_file }:file entrypoint; neverallow * { file_type -exec_type -postinstall_file }:file entrypoint;
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment