Merge "init: lock down access to keychord_device" am: 53cabd6c35
am: 27696cae57
Change-Id: If252f78e4acccfafc7f46ec9d1c2556d66480523
This commit is contained in:
commit
b79e00ac52
1 changed files with 8 additions and 0 deletions
|
@ -363,6 +363,14 @@ neverallow {
|
|||
-system_server
|
||||
-ueventd
|
||||
} hw_random_device:chr_file *;
|
||||
# b/78174219 b/64114943
|
||||
neverallow {
|
||||
domain
|
||||
-init
|
||||
-shell # stat of /dev, getattr only
|
||||
-vendor_init
|
||||
-ueventd
|
||||
} keychord_device:chr_file *;
|
||||
|
||||
# Ensure that all entrypoint executables are in exec_type or postinstall_file.
|
||||
neverallow * { file_type -exec_type -postinstall_file }:file entrypoint;
|
||||
|
|
Loading…
Reference in a new issue