Skip to content
Snippets Groups Projects
Commit e010f08e authored by Nick Kralevich's avatar Nick Kralevich Committed by Gerrit Code Review
Browse files

Merge "neverallow write access to /data/dalvik-cache directories."

parents 8a224775 d9bf7b3f
No related branches found
No related tags found
No related merge requests found
......@@ -354,6 +354,14 @@ neverallow {
-dex2oat
} dalvikcache_data_file:file no_w_file_perms;
neverallow {
domain
-init
-installd
-dex2oat
-zygote
} dalvikcache_data_file:dir no_w_dir_perms;
# Only system_server should be able to send commands via the zygote socket
neverallow { domain -zygote -system_server } zygote:unix_stream_socket connectto;
neverallow { domain -system_server } zygote_socket:sock_file write;
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment