Skip to content
Snippets Groups Projects
Commit a4e83bc5 authored by Tri Vo's avatar Tri Vo Committed by Android (Google) Code Review
Browse files

Merge "Revert "Coredomain can't execute vendor code.""

parents cba25d2c d2315bdf
No related branches found
No related tags found
No related merge requests found
......@@ -154,12 +154,6 @@ expandattribute vendor_executes_system_violators false;
attribute data_between_core_and_vendor_violators;
expandattribute data_between_core_and_vendor_violators false;
# All system domains which violate the requirement of not executing vendor
# binaries/libraries.
# TODO(b/62041836)
attribute system_executes_vendor_violators;
expandattribute system_executes_vendor_violators false;
# hwservices that are accessible from untrusted applications
# WARNING: Use of this attribute should be avoided unless
# absolutely necessary. It is a temporary allowance to aid the
......
......@@ -891,20 +891,6 @@ full_treble_only(`
-crash_dump_exec
-netutils_wrapper_exec
}:file { entrypoint execute execute_no_trans };
# Do not allow system components to execute files from vendor
# except for the ones whitelist here.
neverallow {
coredomain
-init
-system_executes_vendor_violators
-vendor_init
} {
vendor_file_type
-same_process_hal_file
-vndk_sp_file
-vendor_app_file
}:file { execute execute_no_trans };
')
# Only authorized processes should be writing to files in /data/dalvik-cache
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment