Merge "Apply strict SELinux checking of PROT_EXEC on mmap/mprotect calls."

This commit is contained in:
Nick Kralevich 2014-01-02 20:58:34 +00:00 committed by Gerrit Code Review
commit 5b8abdf627
1 changed files with 3 additions and 0 deletions

View File

@ -13,6 +13,9 @@ on early-init
# Set init and its forked children's oom_adj.
write /proc/1/oom_adj -16
# Apply strict SELinux checking of PROT_EXEC on mmap/mprotect calls.
write /sys/fs/selinux/checkreqprot 0
# Set the security context for the init process.
# This should occur before anything else (e.g. ueventd) is started.
setcon u:r:init:s0