Skip to content
Snippets Groups Projects
  • Nick Kralevich's avatar
    Move net.dns* to it's own label. · 4e404290
    Nick Kralevich authored
    Move net.dns* from net_radio_prop to the newly created label
    net_dns_prop. This allows finer grain control over this specific
    property.
    
    Prior to this change, this property was readable to all SELinux domains,
    and writable by the following SELinux domains:
    
      * system_server
      * system_app (apps which run as UID=system)
      * netmgrd
      * radio
    
    This change:
    
    1) Removes read access to this property to everyone EXCEPT untrusted_app
    and system_server.
    2) Limit write access to system_server.
    
    In particular, this change removes read access to priv_apps. Any
    priv_app which ships with the system should not be reading this
    property.
    
    Bug: 34115651
    Test: Device boots, wifi turns on, no problems browsing the internet
    Change-Id: I8a32e98c4f573d634485c4feac91baa35d021d38
    4e404290