diff options
author | Geremy Condra <gcondra@google.com> | 2013-10-31 11:17:23 -0700 |
---|---|---|
committer | Nick Kralevich <nnk@google.com> | 2013-11-07 16:17:32 -0800 |
commit | ddf98fa8cf11000f91329945abc23ee791adfe69 (patch) | |
tree | ecd42d0e6822c2701d0bc364be3ca479860a875b /netd.te | |
parent | 0ea4ac8a12efa2f847625917f35b5cbedec3853a (diff) | |
download | android_external_sepolicy-ddf98fa8cf11000f91329945abc23ee791adfe69.tar.gz android_external_sepolicy-ddf98fa8cf11000f91329945abc23ee791adfe69.tar.bz2 android_external_sepolicy-ddf98fa8cf11000f91329945abc23ee791adfe69.zip |
Neverallow access to the kmem device from userspace.
Change-Id: If26baa947ff462f5bb09b75918a4130097de5ef4
Diffstat (limited to 'netd.te')
-rw-r--r-- | netd.te | 3 |
1 files changed, 0 insertions, 3 deletions
@@ -64,9 +64,6 @@ allow netd device:sock_file write; # Block device access. neverallow netd dev_type:blk_file { read write }; -# Kernel memory access. -neverallow netd kmem_device:chr_file { read write }; - # Setting SELinux enforcing status or booleans. neverallow netd kernel:security { setenforce setbool }; |