Transient SELinux domain for system_server JIT
Create a transient SELinux domain where system_server can perform certain JIT setup. The idea is that system_server will start in the system_server_startup domain, setup certain JIT pages, then perform a one-way transition into the system_server domain. From that point, further JITing operations are disallowed. Bug: 62356545 Test: device boots, no permission errors Change-Id: Ic55b2cc5aba420ebcf62736622e08881a4779004
Showing
- private/domain.te 35 additions, 0 deletionsprivate/domain.te
- private/seapp_contexts 2 additions, 1 deletionprivate/seapp_contexts
- private/system_server.te 5 additions, 0 deletionsprivate/system_server.te
- private/system_server_startup.te 12 additions, 0 deletionsprivate/system_server_startup.te
- private/zygote.te 7 additions, 3 deletionsprivate/zygote.te
- public/domain.te 0 additions, 34 deletionspublic/domain.te
Loading
Please register or sign in to comment