Skip to content
Snippets Groups Projects
  • Nick Kralevich's avatar
    app.te: prevent locks of files on /system · 92c44a57
    Nick Kralevich authored
    Prevent app domains (processes spawned by zygote) from acquiring
    locks on files in /system. In particular, /system/etc/xtables.lock
    must never be lockable by applications, as it will block future
    iptables commands from running.
    
    Test: device boots and no obvious problems.
    Change-Id: Ifd8dc7b117cf4a622b30fd4fffbcab1b76c4421b
    92c44a57