a1cdf2e311
Previously we would mount OTA images with a 'context=...' mount option. This meant that all selinux contexts were ignored in the ota image, limiting the usefulness of selinux in this situation. To fix this the mount has been changed to not overwrite the declared contexts and the policies have been updated to accurately describe the actions being performed by an OTA. Bug: 181182967 Test: Manual OTA of blueline Test: lunch wembley-userdebug; m droid Ignore-AOSP-First: Requires changes to device/mediatek/wembley-sepolicy to be applied simultaneously to avoid breaking builds. Once merged this will be cherry-picked back to AOSP to maintain state. Change-Id: I5eb53625202479ea7e75c27273531257d041e69d
4 lines
150 B
Text
4 lines
150 B
Text
# otapreopt_chroot seclabel
|
|
|
|
# TODO: Only present to allow mediatek/wembley-sepolicy to see it for validation reasons.
|
|
type otapreopt_chroot, domain;
|