Skip to content
Snippets Groups Projects
Commit e112faea authored by Treehugger Robot's avatar Treehugger Robot Committed by Gerrit Code Review
Browse files

Merge "domain: neverallow on setfcap"

parents 70591fed c3f1da99
No related branches found
No related tags found
No related merge requests found
......@@ -653,3 +653,10 @@ neverallow {
# Do not allow kernel module loading except from system,
# vendor, and boot partitions.
neverallow * ~{ system_file rootfs }:system module_load;
# Only allow filesystem caps to be set at build time or
# during upgrade by recovery.
neverallow {
domain
-recovery
} self:capability setfcap;
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment