Skip to content
Snippets Groups Projects
Commit a9ed5f0d authored by Nick Kralevich's avatar Nick Kralevich Committed by android-build-merger
Browse files

Merge "Drop isolated_app auditallow rule." am: dfb7b7e3 am: f5382659

am: 0b6cf545

Change-Id: Ib66a58d8afaaa384f052001aa8de39c778b4ee8e
parents 3ebd6990 0b6cf545
No related branches found
No related tags found
No related merge requests found
......@@ -27,12 +27,9 @@ allow isolated_app self:process ptrace;
# b/32896414: Allow accessing sdcard file descriptors passed to isolated_apps
# by other processes. Open should never be allowed, and is blocked by
# neverallow rules below.
# TODO: consider removing write/append. We want to limit isolated_apps
# ability to mutate files of any type.
# media_rw_data_file is included for sdcardfs, and can be removed if sdcardfs
# is modified to change the secontext when accessing the lower filesystem.
allow isolated_app { sdcard_type media_rw_data_file }:file { read write append getattr lock };
auditallow isolated_app { sdcard_type media_rw_data_file }:file { write append };
# For webviews, isolated_app processes can be forked from the webview_zygote
# in addition to the zygote. Allow access to resources inherited from the
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment