Skip to content
Snippets Groups Projects
  • Joel Galenson's avatar
    Improve neverallow error messages and allow disabling them on userdebug builds. · 5988b565
    Joel Galenson authored
    This patch adds a flag that can be used to ignore neverallow rules.
    By adding
    SELINUX_IGNORE_NEVERALLOWS := true
    into the BoardConfig.mk file, neverallow violations will be ignored
    silently.  This flag can only be enabled on userdebug and eng builds.
    
    Users of this flag should be very careful.  Since it does not work on
    user builds, it must be disabled to pass CTS, and enabling it for
    too long could hide issues that need to be addressed.
    
    As a happy side effect, this patch should also improve the error
    messages when violating a neverallow rules.  Specifically, the file
    and line number should be correct.
    
    Bug: 70950899
    Bug: 33960443
    Test: Built walleye-{user,eng} with and without this new option and
    a neverallow violation.  Built policy for all targets.
    
    Change-Id: Id0d65123cdd230d6b90faa6bb460d544054bb906
    5988b565