platform_system_sepolicy/private/compat/30.0
Hridya Valsaraju 8403ed70de Add a property to enable runtime debugfs restrictions in non-user builds
This patch adds ro.product.enforce_debugfs_restrictions to
property_contexts. When the property is set to true in non-user builds,
init mounts debugfs in early-init to enable boot-time debugfs
initializations and unmounts it on boot complete. Similarly dumpstate
will mount debugfs to collect information from debugfs during bugreport
collection via the dumpstate HAL and unmount debugfs once done. Doing
so will allow non-user builds to keep debugfs disabled during runtime.

Test: make with/without PRODUCT_SET_DEBUGFS_RESTRICTIONS, adb shell am
bugreport
Bug: 184381659

Change-Id: Ib720523c7f94a4f9ce944d46977a3c01ed829414
2021-04-15 22:38:23 -07:00
..
30.0.cil Split gsi_metadata_file and add gsi_metadata_file_type attribute 2021-03-29 03:09:35 +00:00
30.0.compat.cil Add a TODO to remove mlsvendorcompat. 2020-11-23 12:28:21 +00:00
30.0.ignore.cil Add a property to enable runtime debugfs restrictions in non-user builds 2021-04-15 22:38:23 -07:00