Prohibit execute to fs_type other than rootfs for most domains.

Augment the already existing neverallow on loading executable content
from file types other than /system with one on loading executable content
from filesystem types other than the rootfs.  Include exceptions for
appdomain and recovery as required by current policy.

Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>

(cherry picked from commit 4644ac483667befac441bb541733e489d902bacf)

Change-Id: I5e2609a128d1bf982a7a5c3fa3140d1e9346c621
1 file changed