Skip to content
Snippets Groups Projects
  • Jeff Vander Stoep's avatar
    Protect dropbox service data with selinux · 4d3ee1a5
    Jeff Vander Stoep authored
    Create a new label for /data/system/dropbox, and neverallow direct
    access to anything other than init and system_server.
    
    While all apps may write to the dropbox service, only apps with
    android.permission.READ_LOGS, a signature|privileged|development
    permission, may read them. Grant access to priv_app, system_app,
    and platform_app, and neverallow access to all untrusted_apps.
    
    Bug: 31681871
    Test: atest CtsStatsdHostTestCases
    Test: atest DropBoxTest
    Test: atest ErrorsTests
    Change-Id: Ice302b74b13c4d66e07b069c1cdac55954d9f5df
    4d3ee1a5