Merge changes from topic 'blacklist_app_data_execute'
* changes:
fix build: exclude bluetooth from neverallow restriction
Remove platform_app from neverallow execute from /data
Rework neverallow for /data execute permission
diff --git a/app.te b/app.te
index 5215633..1afa4b5 100644
--- a/app.te
+++ b/app.te
@@ -437,6 +437,21 @@
tmpfs
}:lnk_file no_w_file_perms;
+# Blacklist app domains not allowed to execute from /data
+neverallow {
+ bluetooth
+ isolated_app
+ nfc
+ radio
+ shared_relro
+ system_app
+} {
+ data_file_type
+ -dalvikcache_data_file
+ -system_data_file # shared libs in apks
+ -apk_data_file
+}:file no_x_file_perms;
+
# Foreign dex profiles are just markers. Prevent apps to do anything but touch them.
neverallow appdomain user_profile_foreign_dex_data_file:file rw_file_perms;
neverallow appdomain user_profile_foreign_dex_data_file:dir { open getattr read ioctl remove_name };
diff --git a/domain.te b/domain.te
index 38a6db8..7da2340 100644
--- a/domain.te
+++ b/domain.te
@@ -305,9 +305,7 @@
# Protect most domains from executing arbitrary content from /data.
neverallow {
domain
- -untrusted_app
- -priv_app
- -shell
+ -appdomain
} {
data_file_type
-dalvikcache_data_file
@@ -519,6 +517,11 @@
-zygote
} shell:process { transition dyntransition };
+# Only domains spawned from zygote and runas may have the appdomain attribute.
+neverallow { domain -runas -zygote } {
+ appdomain -shell userdebug_or_eng(`-su') -bluetooth
+}:process { transition dyntransition };
+
# Minimize read access to shell- or app-writable symlinks.
# This is to prevent malicious symlink attacks.
neverallow {