Introduce system_file_type
system_file_type is a new attribute used to identify files which exist on the /system partition. It's useful for allow rules in init, which are based off of a blacklist of writable files. Additionally, it's useful for constructing neverallow rules to prevent regressions. Additionally, add commented out tests which enforce that all files on the /system partition have the system_file_type attribute. These tests will be uncommented in a future change after all the device-specific policies are cleaned up. Test: Device boots and no obvious problems. Change-Id: Id9bae6625f042594c8eba74ca712abb09702c1e5
Showing
- public/attributes 4 additions, 0 deletionspublic/attributes
- public/bootanim.te 1 addition, 1 deletionpublic/bootanim.te
- public/bootstat.te 1 addition, 1 deletionpublic/bootstat.te
- public/bufferhubd.te 1 addition, 1 deletionpublic/bufferhubd.te
- public/cameraserver.te 1 addition, 1 deletionpublic/cameraserver.te
- public/clatd.te 1 addition, 1 deletionpublic/clatd.te
- public/cppreopts.te 1 addition, 1 deletionpublic/cppreopts.te
- public/crash_dump.te 1 addition, 1 deletionpublic/crash_dump.te
- public/dex2oat.te 1 addition, 1 deletionpublic/dex2oat.te
- public/dhcp.te 1 addition, 1 deletionpublic/dhcp.te
- public/dnsmasq.te 1 addition, 1 deletionpublic/dnsmasq.te
- public/domain.te 5 additions, 5 deletionspublic/domain.te
- public/drmserver.te 1 addition, 1 deletionpublic/drmserver.te
- public/dumpstate.te 1 addition, 1 deletionpublic/dumpstate.te
- public/e2fs.te 1 addition, 1 deletionpublic/e2fs.te
- public/file.te 15 additions, 15 deletionspublic/file.te
- public/fingerprintd.te 1 addition, 1 deletionpublic/fingerprintd.te
- public/fsck.te 1 addition, 1 deletionpublic/fsck.te
- public/gatekeeperd.te 1 addition, 1 deletionpublic/gatekeeperd.te
- public/healthd.te 1 addition, 1 deletionpublic/healthd.te
Please register or sign in to comment