20.08.2015 Views

SELinux in Android Lollipop and M

lss2015_selinuxinandroidlollipopandm_smalley

lss2015_selinuxinandroidlollipopandm_smalley

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

The Chrome for <strong>Android</strong> s<strong>and</strong>box●●●●Comb<strong>in</strong>es multi-process architecture with UID isolation.App service components can be declared with aprocess=”name” <strong>and</strong> an isolatedProcess=”true” attribute.<strong>Android</strong> will run such services <strong>in</strong> a separate process <strong>and</strong>UID from the ma<strong>in</strong> app.This process has no <strong>Android</strong> permissions <strong>and</strong> the usualDAC restrictions, i.e. cannot read or write the files of thema<strong>in</strong> app unless they are world accessible.15

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!