Skip to content
Snippets Groups Projects
  • Alex Klyubin's avatar
    Assert untrusted apps can't add or list hwservicemanager · 5c5b6263
    Alex Klyubin authored
    This adds a neverallow rules which checks that SELinux app domains
    which host arbitrary code are not allowed to access hwservicemanager
    operations other than "find" operation for which there already are
    strict neverallow rules in the policy.
    
    Test: mmm system/sepolicy -- neverallow-only change
    Bug: 34454312
    Change-Id: I3b80c6ae2c254495704e0409e0c5c88f6ce3a6a7
    5c5b6263