Restrict the ability to set SELinux enforcing mode to init.
Also make su and shell permissive in non-user builds to allow
use of setenforce without violating the neverallow rule.
Change-Id: Ie76ee04e90d5a76dfaa5f56e9e3eb7e283328a3f
Signed-off-by:
Stephen Smalley <sds@tycho.nsa.gov>
Showing
- Android.mk 2 additions, 0 deletionsAndroid.mk
- domain.te 2 additions, 2 deletionsdomain.te
- init.te 1 addition, 1 deletioninit.te
- shell.te 3 additions, 0 deletionsshell.te
- shell_user.te 8 additions, 0 deletionsshell_user.te
- su.te 3 additions, 0 deletionssu.te
- te_macros 2 additions, 6 deletionste_macros
- unconfined.te 1 addition, 1 deletionunconfined.te
shell_user.te
0 → 100644
Please register or sign in to comment