Merge "neverallow cache_file and derivatives execute"
This commit is contained in:
commit
72aeb0126a
1 changed files with 2 additions and 0 deletions
|
@ -294,6 +294,8 @@ neverallow {
|
|||
-appdomain # for oemfs
|
||||
-recovery # for /tmp/update_binary in tmpfs
|
||||
} { fs_type -rootfs }:file execute;
|
||||
# Files from cache should never be executed
|
||||
neverallow domain { cache_file cache_backup_file }:file execute;
|
||||
|
||||
# Only the init property service should write to /data/property.
|
||||
neverallow { domain -init } property_data_file:dir no_w_dir_perms;
|
||||
|
|
Loading…
Reference in a new issue