summaryrefslogtreecommitdiff
path: root/docs/html/sdk/api_diff/10/changes
diff options
context:
space:
mode:
authorRobert Craig <rpcraig@tycho.ncsc.mil>2013-12-02 10:24:23 -0500
committerRobert Craig <rpcraig@tycho.ncsc.mil>2013-12-06 08:51:20 -0500
commit99a626c2719e1965364fad543101799f527e28ca (patch)
tree1371ff27a0b08401d7f844d837589f16447205ed /docs/html/sdk/api_diff/10/changes
parent6e2d0c1d91f644ab50e0c0b7cae4306262a4ca41 (diff)
Augment SELinuxMMAC functionality.
* No longer support a package name stanza outside of a signature tag. Package names, by themselves, have no security associated with them in Android and thus we should not be allowing or encouraging this type of policy. * Allow for nested package name stanzas inside signature stanzas. There are cases where a finer distinction needs to be made among apps signed with the same cert. New code allows a different seinfo tag to be assigned to the listed package names signed by the parent cert. When a determination needs to be made concerning seinfo assignments, the inner seinfo tag takes precedence over the outer seinfo labels which are assigned to just the signature. * Temp structures are now used to parse new policy files until the entire xml file is parsed and deemed correct, at which time the temp structures are copied over to the permanent class structures. This ensures that any structural errors with the policy will not result in partial loads. * Valid stanzas look like the following with the inner package piece being optional. <signer signature=""> <seinfo value=""/> <package name=""> <seinfo value=""/> </package> <signer> <default> <seinfo value=""/> </default> Change-Id: Ia204d71211776dcf9b2dcc86ad6d77c4ad39dc25
Diffstat (limited to 'docs/html/sdk/api_diff/10/changes')
0 files changed, 0 insertions, 0 deletions