|
Hi, On 8/29/2013 2:10 PM, Stephen Smalley
wrote:
Apologies to both Stephen and William. I was a bit "terse" in this part of the discussion since me email was getting a bit long :-)On 08/29/2013 12:20 PM, Andreas Wolf wrote:While working on the SEAndroid side of the project we think we found some improvements that may be of interest to the wider audience. Maybe these can be discussed by this group? We did actually use the SEAndroidManager for a while, but replaced it with the feature in "init," I tried to describe above. I believe the issue addressed is also present when using the SEAdmin, since the "boot" step that Stephen references is the "BOOT_COMPLETED" sent through the Android framework, which is still too late. To clarify, the issue is the use of an SE Boolean, that has a default value to disallow the use of a device (via a service started by "init"). Through an MDM/SEAdmin tool I now re-provision a device to change the value to "allow". I do not want to send up a new SE policy file with new defaults, but instead just want to change the value of that one Boolean (otherwise, I would have not used a Boolean in the first place) and thus make the device functional. If I now reboot the device, I will have the default value of that SE Boolean "active" when the kernel starts until the mechanism "kicks in" that changes it to the new value. Any mechanism based on an Android app, started after the framework has become active, will be too late in this case. Does this help? Or am I still missing something? Cheers, Andreas =:-) --
--
This message was distributed to subscribers of the seandroid-list mailing list.
If you no longer wish to subscribe, send mail to [email protected] with
the words "unsubscribe seandroid-list" without quotes as the message.
Remember, Experience Gained is Directly Proportional to the Amount of Equipment Destroyed! |
- Joining this list - with some comments Andreas Wolf
- Re: Joining this list - with some comments William Roberts
- Re: Joining this list - with some comments Stephen Smalley
- Re: Joining this list - with some comments Andreas Wolf
- Re: Joining this list - with some comments Stephen Smalley
- Re: Joining this list - with some comment... Andreas Wolf
- Re: Joining this list - with some comments rpcraig
- Re: Joining this list - with some comments Ken Black
- Re: Joining this list - with some comments Joshua Brindle
- Re: Joining this list - with some comment... Joshua Brindle
- Re: Joining this list - with some comments Robert Craig
- Re: Joining this list - with some comment... Ken Black
- Re: Joining this list - with some co... Stephen Smalley
- Re: Joining this list - with some comments Andreas Wolf
