Introduce system_file_type
system_file_type is a new attribute used to identify files which exist on the /system partition. It's useful for allow rules in init, which are based off of a blacklist of writable files. Additionally, it's useful for constructing neverallow rules to prevent regressions. Additionally, add commented out tests which enforce that all files on the /system partition have the system_file_type attribute. These tests will be uncommented in a future change after all the device-specific policies are cleaned up. Test: Device boots and no obvious problems. Change-Id: Id9bae6625f042594c8eba74ca712abb09702c1e5
Showing
- public/hwservicemanager.te 1 addition, 1 deletionpublic/hwservicemanager.te
- public/idmap.te 1 addition, 1 deletionpublic/idmap.te
- public/init.te 7 additions, 7 deletionspublic/init.te
- public/inputflinger.te 1 addition, 1 deletionpublic/inputflinger.te
- public/install_recovery.te 1 addition, 1 deletionpublic/install_recovery.te
- public/installd.te 1 addition, 1 deletionpublic/installd.te
- public/keystore.te 1 addition, 1 deletionpublic/keystore.te
- public/llkd.te 1 addition, 1 deletionpublic/llkd.te
- public/lmkd.te 1 addition, 1 deletionpublic/lmkd.te
- public/logd.te 1 addition, 1 deletionpublic/logd.te
- public/mediadrmserver.te 1 addition, 1 deletionpublic/mediadrmserver.te
- public/mediaextractor.te 1 addition, 1 deletionpublic/mediaextractor.te
- public/mediametrics.te 1 addition, 1 deletionpublic/mediametrics.te
- public/mediaserver.te 1 addition, 1 deletionpublic/mediaserver.te
- public/mtp.te 1 addition, 1 deletionpublic/mtp.te
- public/netd.te 1 addition, 1 deletionpublic/netd.te
- public/netutils_wrapper.te 1 addition, 1 deletionpublic/netutils_wrapper.te
- public/otapreopt_chroot.te 1 addition, 1 deletionpublic/otapreopt_chroot.te
- public/otapreopt_slot.te 1 addition, 1 deletionpublic/otapreopt_slot.te
- public/performanced.te 1 addition, 1 deletionpublic/performanced.te
Please register or sign in to comment