Skip to content
Snippets Groups Projects
Commit b081cc1e authored by Stephen Smalley's avatar Stephen Smalley Committed by Nick Kralevich
Browse files

Remove mount-related permissions from unconfined domains.


Only allow to specific domains as required, and add a neverallow
to prevent allowing it to other domains not explicitly whitelisted.
sdcard_type is exempted from the neverallow since more domains
require the ability to mount it, including device-specific domains.

Change-Id: Ia6476d1c877f5ead250749fb12bff863be5e9f27
Signed-off-by: default avatarStephen Smalley <sds@tycho.nsa.gov>
parent 48b18832
No related branches found
No related tags found
No related merge requests found
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment