[Toybox] New Toy: toys/android/runconuid

Zach Riggle riggle at google.com
Fri May 20 13:01:59 PDT 2016


I believe we decided in a different thread just to put it next to the su
binary as a stand-alone tool that only goes on userdebug devices and call
it a day.
On Fri, May 20, 2016 at 1:00 PM enh <enh at google.com> wrote:

> (i was waiting to see what the security guys think of this. whether
> they think this is generally useful, whether there are changes they'd
> like, whether this should just be in vendor/google/...)
>
> On Fri, May 20, 2016 at 11:44 AM, Rob Landley <rob at landley.net> wrote:
> > On 05/17/2016 04:42 PM, Zach Riggle wrote:
> >> I would like to contribute a new Android-specific toy which extends the
> >> standard functionality of runcon to enable transitioning to a chosen
> >> tuple of (uid, gid, groups, secontext) when SELinux is not enforcing,
> >> then switching SELinux to enforcing mode before the first instruction of
> >> the new process is executed (i.e. with ptrace).
> >>
> >> I have already created and tested the toy, but I would like feedback /
> >> guidance on:
> >>
> >> - Whether Toybox is willing to accept the toy
> >> - Whether to submit the tool directly to toys/android or to toys/pending
> >> - Appropriate mechanism for submitting patches
> >
> > Any follow-up on this?
> >
> > Would you like to submit the patch to the list?
> >
> > Rob
> > _______________________________________________
> > Toybox mailing list
> > Toybox at lists.landley.net
> > http://lists.landley.net/listinfo.cgi/toybox-landley.net
>
>
>
> --
> Elliott Hughes - http://who/enh - http://jessies.org/~enh/
> Android native code/tools questions? Mail me/drop by/add me as a reviewer.
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.landley.net/pipermail/toybox-landley.net/attachments/20160520/0246bd4d/attachment-0002.htm>


More information about the Toybox mailing list