Skip to content
Snippets Groups Projects
  • Jeff Vander Stoep's avatar
    Improve neverallows on /proc and /sys · 3079d01a
    Jeff Vander Stoep authored
    Access to these files was removed in Oreo. Enforce that access is not
    granted by partners via neverallow rule.
    
    Also disallow most untrusted app access to net.dns.* properties.
    
    Bug: 77225170
    Test: system/sepolicy/tools/build_policies.sh
    Change-Id: I85b634af509203393dd2d9311ab5d30c65f157c1
    (cherry picked from commit 886aa54b)
    3079d01a