Skip to content
Snippets Groups Projects
Commit c5266df9 authored by Eino-Ville Talvala's avatar Eino-Ville Talvala Committed by Jeff Vander Stoep
Browse files

Rework neverallow for /data execute permission

Previously appdomains allowed to execute off of /data
where whitelisted. This had the unfortunate side effect of
disallowing the creation of device specific app domains
with fewer permissions than untrusted_app. Instead grant
all apps a neverallow exemption and blacklist specific app
domains that should still abide by the restriction.

This allows devices to add new app domains that need
/data execute permission without conflicting with this rule.

Bug: 26906711
Change-Id: Ia876cc1dfd5b12908c59bd9e8620a6b890729c28
parent 493df204
No related branches found
No related tags found
No related merge requests found
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment