1. seandroid
  2. Untitled project
  3. external/sepolicy

Commits

Stephen Smalley  committed 19ce13e

Allow kernel execmem for recovery.

...until we set up its own domain.

Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>

  • Participants
  • Parent commits abde342
  • Branches seandroid, seandroid-4.4

Comments (0)

Files changed (1)

File kernel.te

View file
  • Ignore whitespace
 
 # Set checkreqprot by init.rc prior to switching to init domain.
 allow kernel self:security setcheckreqprot;
+
+# For /sbin/recovery until we set up its own domain.
+allow kernel self:process execmem;