Merge "Introduce security.lower_kptr_restrict property" am: 24a21867e7
Original change: https://android-review.googlesource.com/c/platform/system/core/+/1455185 Change-Id: I23669ae623e3bdd3694766dda3704a97c3db2144
This commit is contained in:
commit
8ff9efc482
1 changed files with 8 additions and 0 deletions
|
|
@ -1041,6 +1041,14 @@ on property:security.perf_harden=1
|
||||||
write /proc/sys/kernel/perf_cpu_time_max_percent 25
|
write /proc/sys/kernel/perf_cpu_time_max_percent 25
|
||||||
write /proc/sys/kernel/perf_event_mlock_kb 516
|
write /proc/sys/kernel/perf_event_mlock_kb 516
|
||||||
|
|
||||||
|
# This property can be set only on userdebug/eng. See neverallow rule in
|
||||||
|
# /system/sepolicy/private/property.te .
|
||||||
|
on property:security.lower_kptr_restrict=1
|
||||||
|
write /proc/sys/kernel/kptr_restrict 0
|
||||||
|
|
||||||
|
on property:security.lower_kptr_restrict=0
|
||||||
|
write /proc/sys/kernel/kptr_restrict 2
|
||||||
|
|
||||||
|
|
||||||
# on shutdown
|
# on shutdown
|
||||||
# In device's init.rc, this trigger can be used to do device-specific actions
|
# In device's init.rc, this trigger can be used to do device-specific actions
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue