Skip to content
Snippets Groups Projects
  • Stephen Smalley's avatar
    Remove zygote write access to system_data_file. · df48bd2c
    Stephen Smalley authored
    
    These rules seem to be a legacy of old Android or perhaps old policy
    before we began splitting types on /data.  I have not been able to
    trigger the auditallow rules on AOSP master.  Reduce the rules to
    only read access to system data.  If we need write access to some
    specific directory under /data, we should introduce a type for it.
    
    Change-Id: I780835950cc366c97b7d0901fc73527d9ea479b1
    Signed-off-by: default avatarStephen Smalley <sds@tycho.nsa.gov>
    df48bd2c