Skip to content
Snippets Groups Projects
Select Git revision
  • android-7.1.2_r28_klist
  • master default protected
  • pie-cts-release
  • pie-vts-release
  • pie-cts-dev
  • oreo-mr1-iot-release
  • sdk-release
  • oreo-m6-s4-release
  • oreo-m4-s12-release
  • pie-release
  • pie-r2-release
  • pie-r2-s1-release
  • oreo-vts-release
  • oreo-cts-release
  • oreo-dev
  • oreo-mr1-dev
  • pie-gsi
  • pie-platform-release
  • pie-dev
  • oreo-cts-dev
  • android-o-mr1-iot-release-1.0.4
  • android-9.0.0_r8
  • android-9.0.0_r7
  • android-9.0.0_r6
  • android-9.0.0_r5
  • android-8.1.0_r46
  • android-8.1.0_r45
  • android-n-iot-release-smart-display-r2
  • android-vts-8.1_r5
  • android-cts-8.1_r8
  • android-cts-8.0_r12
  • android-cts-7.1_r20
  • android-cts-7.0_r24
  • android-o-mr1-iot-release-1.0.3
  • android-cts-9.0_r1
  • android-8.1.0_r43
  • android-8.1.0_r42
  • android-n-iot-release-smart-display
  • android-p-preview-5
  • android-9.0.0_r3
40 results

AndroidSystemSEPolicy

  • Clone with SSH
  • Clone with HTTPS
  • user avatar
    Stephen Smalley authored
    Fix two neverallow rules that yield Invalid SELinux context
    warnings from the CTS SELinuxTest.
    
    For transitions from app domains, we only need to check
    { domain -appdomain } (i.e. domains other than app domains),
    not ~appdomain (i.e. all types other than app domains).  Otherwise
    SELinuxTest tries to generate contexts with the r role and
    non-domain types for testing since the target class is process,
    and such contexts are invalid.
    
    For keeping file_type and fs_type exclusive, we only need to
    check associate permission, not all filesystem permissions, as
    only associate takes a file type as the source context.  Otherwise
    SELinuxTest tries to generate contexts with the r role and
    non-domain types for testing filesystem permissions other than
    associate, since the source of such checks is normally a process
    context.
    
    Signed-off-by: default avatarStephen Smalley <sds@tycho.nsa.gov>
    
    (cherry picked from commit 21ada26d)
    
    Change-Id: I3346584da9b89f352864dcc30dde06d6bf42e98e
    d990a78f
    History
    Name Last commit Last update