Merge "init: lock down access to keychord_device" am: 53cabd6c35

am: 27696cae57

Change-Id: If252f78e4acccfafc7f46ec9d1c2556d66480523
This commit is contained in:
Mark Salyzyn 2018-04-17 13:09:38 -07:00 committed by android-build-merger
commit b79e00ac52

View file

@ -363,6 +363,14 @@ neverallow {
-system_server
-ueventd
} hw_random_device:chr_file *;
# b/78174219 b/64114943
neverallow {
domain
-init
-shell # stat of /dev, getattr only
-vendor_init
-ueventd
} keychord_device:chr_file *;
# Ensure that all entrypoint executables are in exec_type or postinstall_file.
neverallow * { file_type -exec_type -postinstall_file }:file entrypoint;