Skip to content
Snippets Groups Projects
Commit a2cf96bc authored by Nick Kralevich's avatar Nick Kralevich Committed by android-build-merger
Browse files

Merge "Ensure /sys restrictions for isolated_apps"

am: eb1ae188

Change-Id: I9f8a35d86fefecc0485cf57bc2e2cf876d770fc9
parents ad2a86d6 eb1ae188
No related branches found
No related tags found
No related merge requests found
......@@ -103,3 +103,11 @@ neverallow isolated_app { usb_device usbaccessory_device }:chr_file *;
# Restrict the webview_zygote control socket.
neverallow isolated_app webview_zygote_socket:sock_file write;
# Limit the /sys files which isolated_app can access. This is important
# for controlling isolated_app attack surface.
neverallow isolated_app {
sysfs_type
-sysfs_devices_system_cpu
-sysfs_usb # TODO: check with audio team if needed for isolated_app (b/28417852)
}:file no_rw_file_perms;
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment