Remove kmem_device selinux type.
kmem_device was used to label /dev/mem and /dev/kmem. We already have multiple layers of protection against those /dev nodes being present on devices. CTS checks that /dev/mem and /dev/kmem don't exist: https://android.googlesource.com/platform/cts/+/master/tests/tests/permission/src/android/permission/cts/FileSystemPermissionTest.java#233 VTS enforces our base kernel configs, which have CONFIG_DEVKMEM and CONFIG_DEVMEM disabled: https://android.googlesource.com/kernel/configs/+/master/android-4.9/android-base.config#2 Bug: 110962171 Test: m selinux_policy Change-Id: I246740684218dee0cddf81dabf84d4763a753cde
Showing
- private/compat/28.0/28.0.cil 1 addition, 0 deletionsprivate/compat/28.0/28.0.cil
- private/file_contexts 0 additions, 2 deletionsprivate/file_contexts
- public/device.te 0 additions, 1 deletionpublic/device.te
- public/domain.te 0 additions, 8 deletionspublic/domain.te
- public/init.te 0 additions, 1 deletionpublic/init.te
- public/shell.te 0 additions, 1 deletionpublic/shell.te
- public/ueventd.te 2 additions, 2 deletionspublic/ueventd.te
- public/vendor_init.te 0 additions, 1 deletionpublic/vendor_init.te
Please register or sign in to comment