diff --git a/domain.te b/domain.te index 6cf7be34b..243c992f3 100644 --- a/domain.te +++ b/domain.te @@ -329,3 +329,6 @@ neverallow { domain -recovery } system_block_device:blk_file write; # No domains other than install_recovery or recovery can write to recovery. neverallow { domain -install_recovery -recovery } recovery_block_device:blk_file write; + +# Only servicemanager should be able to register with binder as the context manager +neverallow { domain -servicemanager } *:binder set_context_mgr; diff --git a/unconfined.te b/unconfined.te index 1a5194232..32044eccc 100644 --- a/unconfined.te +++ b/unconfined.te @@ -90,4 +90,4 @@ allow unconfineddomain contextmount_type:notdevfile_class_set r_file_perms; allow unconfineddomain node_type:node *; allow unconfineddomain netif_type:netif *; allow unconfineddomain domain:peer recv; -allow unconfineddomain { domain -init }:binder { call transfer set_context_mgr }; +allow unconfineddomain { domain -init }:binder { call transfer };