property.te: delete security_prop
am: ee751c33c5
Change-Id: I2acdab95a5d2302a10ed6cf57c0705edc480bc6c
This commit is contained in:
commit
b1985a8498
3 changed files with 0 additions and 5 deletions
|
@ -65,7 +65,6 @@ ro.device_owner u:object_r:device_logging_prop:s0
|
|||
|
||||
# selinux non-persistent properties
|
||||
selinux.restorecon_recursive u:object_r:restorecon_prop:s0
|
||||
selinux. u:object_r:security_prop:s0
|
||||
|
||||
# default property context
|
||||
* u:object_r:default_prop:s0
|
||||
|
|
|
@ -229,9 +229,6 @@ neverallow { domain -recovery } self:capability2 mac_admin;
|
|||
# It is sealed.
|
||||
neverallow * kernel:security load_policy;
|
||||
|
||||
# Only init and the system_server shall use the property_service.
|
||||
neverallow { domain -init -system_server } security_prop:property_service set;
|
||||
|
||||
# Only init prior to switching context should be able to set enforcing mode.
|
||||
# init starts in kernel domain and switches to init domain via setcon in
|
||||
# the init.rc, so the setenforce occurs while still in kernel. After
|
||||
|
|
|
@ -35,7 +35,6 @@ type powerctl_prop, property_type, core_property_type;
|
|||
type radio_prop, property_type, core_property_type;
|
||||
type restorecon_prop, property_type, core_property_type;
|
||||
type safemode_prop, property_type;
|
||||
type security_prop, property_type, core_property_type;
|
||||
type shell_prop, property_type, core_property_type;
|
||||
type system_prop, property_type, core_property_type;
|
||||
type system_radio_prop, property_type, core_property_type;
|
||||
|
|
Loading…
Reference in a new issue