commit | 5fe69e082ac44aba637469fc59fee9f311c8d20b | [log] [tgz] |
---|---|---|
author | Marco Ballesio <balejs@google.com> | Thu Sep 03 12:07:33 2020 -0700 |
committer | Marco Ballesio <balejs@google.com> | Thu Sep 03 14:12:17 2020 -0700 |
tree | c7f717e5b5adecfae358a8718ac97b6d3f0b0b7d | |
parent | bc1fbf57fa504c5a958fc3005ab83669244b58e4 [diff] |
sepolicy: restrict BINDER_FREEZE to system_server BINDER_FREEZE is used to block ipc transactions to frozen processes, so only system_server must be allowed to use it. Bug: 143717177 Test: manually verified that attempts to use BINDER_FREEZE by processes other than system_server receive a sepolicy denial Test: verified that system_server can enable/disable the freezer in binder Change-Id: I0fae3585c6ec409809e8085c1cc9862be4755889