On 01/24/2013 04:37 PM, William Roberts wrote:
I have a set of patches to come out after my current changes are
accepted that will remove system_app from being able to manage mmac
and selinux.

Instead seapp contexts will move the seandroid manager package to
mac_manage domain, where it will have permission.

Any objections / comments?

If you plan to use the device admin APIs, then you can get rid of SEAndroidManager altogether and remove access for all app domains, because then the changes are made by the DevicePolicyManager inside the system_server in response to API invocations from device admin apps. SEAndroidAdmin is a sample device admin app.

I am initiating pull requests to the seandroid repos until our backlog
at AOSP is cleared out, any objections on that?

That's fine.


--
This message was distributed to subscribers of the seandroid-list mailing list.
If you no longer wish to subscribe, send mail to [email protected] with
the words "unsubscribe seandroid-list" without quotes as the message.

Reply via email to