platform_build/target/board
Stephen Smalley 75770de701 Only allow toolbox exec where /system exec was already allowed.
When the toolbox domain was introduced, we allowed all domains to exec it
to avoid breakage.  However, only domains that were previously allowed the
ability to exec /system files would have been able to do this prior to the
introduction of the toolbox domain.  Remove the rule from domain.te and add
rules to all domains that are already allowed execute_no_trans to system_file.
Requires coordination with device-specific policy changes with the same Change-Id.

Change-Id: Ie46209f0412f9914857dc3d7c6b0917b7031aae5
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
2015-08-25 11:46:12 -04:00
..
generic Only allow toolbox exec where /system exec was already allowed. 2015-08-25 11:46:12 -04:00
generic_arm64 Bump generic_arm64 system partition size to 1200 MB. 2015-07-27 11:01:50 -07:00
generic_armv5 Remove ARCH_ARM_HAVE_TLS_REGISTER. 2015-02-13 20:51:12 -08:00
generic_mips Drop BOARD_SEPOLICY_UNION. 2015-04-01 10:33:24 -04:00
generic_mips64 Build: Update Mips64 generic build for ART 2015-05-06 21:00:44 -07:00
generic_x86 Drop BOARD_SEPOLICY_UNION. 2015-04-01 10:33:24 -04:00
generic_x86_64 Define BOARD_SEPOLICY_DIRS for 64-bit emulators. 2015-04-29 09:55:08 -04:00
Android.mk Don't bother going through the source tree 2013-08-09 10:08:30 -07:00