Skip to content
Snippets Groups Projects
Commit df3d1f86 authored by Nick Kralevich's avatar Nick Kralevich Committed by Android Git Automerger
Browse files

am dcfcdbdf: Merge "Don\'t allow ptrace on keystore"

* commit 'dcfcdbdf':
  Don't allow ptrace on keystore
parents 7fb77b81 dcfcdbdf
Branches
Tags
No related merge requests found
...@@ -9,7 +9,7 @@ allow debuggerd self:capability2 { syslog }; ...@@ -9,7 +9,7 @@ allow debuggerd self:capability2 { syslog };
allow debuggerd domain:dir r_dir_perms; allow debuggerd domain:dir r_dir_perms;
allow debuggerd domain:file r_file_perms; allow debuggerd domain:file r_file_perms;
allow debuggerd domain:lnk_file read; allow debuggerd domain:lnk_file read;
allow debuggerd { domain -init -ueventd -watchdogd -healthd -adbd }:process ptrace; allow debuggerd { domain -init -ueventd -watchdogd -healthd -adbd -keystore }:process ptrace;
security_access_policy(debuggerd) security_access_policy(debuggerd)
allow debuggerd system_data_file:dir create_dir_perms; allow debuggerd system_data_file:dir create_dir_perms;
allow debuggerd system_data_file:dir relabelfrom; allow debuggerd system_data_file:dir relabelfrom;
......
...@@ -15,7 +15,7 @@ allow keystore tee:unix_stream_socket connectto; ...@@ -15,7 +15,7 @@ allow keystore tee:unix_stream_socket connectto;
### ###
### Neverallow rules ### Neverallow rules
### ###
### Protect our files from others ### Protect ourself from others
### ###
neverallow { domain -keystore } keystore_data_file:dir ~{ open create read getattr setattr search relabelto }; neverallow { domain -keystore } keystore_data_file:dir ~{ open create read getattr setattr search relabelto };
...@@ -23,3 +23,5 @@ neverallow { domain -keystore } keystore_data_file:notdevfile_class_set ~{ relab ...@@ -23,3 +23,5 @@ neverallow { domain -keystore } keystore_data_file:notdevfile_class_set ~{ relab
neverallow { domain -keystore -init -kernel -recovery } keystore_data_file:dir *; neverallow { domain -keystore -init -kernel -recovery } keystore_data_file:dir *;
neverallow { domain -keystore -init -kernel -recovery } keystore_data_file:notdevfile_class_set *; neverallow { domain -keystore -init -kernel -recovery } keystore_data_file:notdevfile_class_set *;
neverallow domain keystore:process ptrace;
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment