file_context: explicitly label all file context files
file_context files need to be explicitly labeled as they are now split
across system and vendor and won't have the generic world readable
'system_file' label.
Bug: 36002414
Test: no new 'file_context' denials at boot complete on sailfish
Test: successfully booted into recovery without denials and sideloaded
OTA update.
Test: ./cts-tradefed run singleCommand cts --skip-device-info \
--skip-preconditions --skip-connectivity-check --abi \
arm64-v8a --module CtsSecurityHostTestCases -t \
android.security.cts.SELinuxHostTest#testAospFileContexts
Change-Id: I603157e9fa7d1de3679d41e343de397631666273
Signed-off-by:
Sandeep Patil <sspatil@google.com>
Showing
- private/adbd.te 1 addition, 0 deletionsprivate/adbd.te
- private/file_contexts 5 additions, 3 deletionsprivate/file_contexts
- private/system_server.te 2 additions, 0 deletionsprivate/system_server.te
- public/file.te 3 additions, 0 deletionspublic/file.te
- public/init.te 3 additions, 0 deletionspublic/init.te
- public/installd.te 2 additions, 0 deletionspublic/installd.te
- public/kernel.te 3 additions, 0 deletionspublic/kernel.te
- public/recovery.te 2 additions, 0 deletionspublic/recovery.te
- public/ueventd.te 3 additions, 0 deletionspublic/ueventd.te
- public/vold.te 3 additions, 0 deletionspublic/vold.te
Please register or sign in to comment