OSDN Git Service

Only allow toolbox exec where /system exec was already allowed.
authorStephen Smalley <sds@tycho.nsa.gov>
Tue, 25 Aug 2015 15:42:17 +0000 (11:42 -0400)
committerStephen Smalley <sds@tycho.nsa.gov>
Tue, 25 Aug 2015 15:46:12 +0000 (11:46 -0400)
commit75770de7019da0d3c6bbed1597414390bbaef266
tree0afdd247cffef521c3d5cebc1d5fb4007a37ec75
parentbcbd4eb9fb9c82f35ca46cc9b976a59b6c1645d4
Only allow toolbox exec where /system exec was already allowed.

When the toolbox domain was introduced, we allowed all domains to exec it
to avoid breakage.  However, only domains that were previously allowed the
ability to exec /system files would have been able to do this prior to the
introduction of the toolbox domain.  Remove the rule from domain.te and add
rules to all domains that are already allowed execute_no_trans to system_file.
Requires coordination with device-specific policy changes with the same Change-Id.

Change-Id: Ie46209f0412f9914857dc3d7c6b0917b7031aae5
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
target/board/generic/sepolicy/goldfish_setup.te