[roll] Roll fuchsia Revert "[sestarnix] Add default exceptions config, and enforce exec checks" This reverts commit 1e5a482d452c8b46b7d91f3a93e91b860e5297d4. Reason for revert: Interferes with system suspension. Original-Bug: 391664952 Original change's description: > [sestarnix] Add default exceptions config, and enforce exec checks > > Containers with SELinux enabled will now run with a built-in set of > access-check exceptions, unless a configuration file or the > special "#strict" setting, are specified. This simplifies migration > away from the todo_check_permission() workaround, and allows tests > in the SELinux Test Suite to pass, by running the suite with no > exceptions applied. > > The exceptions configuration format now accepts both b/<id> and > https://fxbug.dev/<id> forms. > > The file:entrypoint and file:execute_no_trans permissions are now > enforced on exec(), with the set of access-check exceptions > required by some current containers baked-into the default config. > > Original-Bug: 389914184, 330904217, 390458405, 368235493, 390739936, 368236372 > Change-Id: Ia4129e05526b686d685bab978958293a9c95efa1 > Original-Reviewed-on: https://fuchsia-review.googlesource.com/c/fuchsia/+/1189072 > Fuchsia-Auto-Submit: Wez <wez@google.com> > Reviewed-by: Kevin Lindkvist <lindkvist@google.com> > Commit-Queue: Auto-Submit <auto-submit@fuchsia-infra.iam.gserviceaccount.com> Original-Bug: 389914184, 330904217, 390458405, 368235493, 390739936, 368236372 Original-Reviewed-on: https://fuchsia-review.googlesource.com/c/fuchsia/+/1191534 Original-Revision: 04ff916cb56028be16fbdc4b1bfce70d37d8dc4c GitOrigin-RevId: 68c0dde56fa9b7806e69b31f7aad48a68a2d4468 Change-Id: Ic4bb09fd1bf7d34a935e672b02b1b93b79abe304
This repository contains Fuchsia's Global Integration manifest files.
All changes should be made to the internal version of this repository. Our infrastructure automatically updates this version when the internal one changes.
Currently all changes must be made by a Google employee. Non-Google employees wishing to make a change can ask for assistance in one of the communication channels documented at get involved.
First install Jiri.
Next run:
$ jiri init $ jiri import minimal https://fuchsia.googlesource.com/integration $ jiri update
Third party projects should have their own subdirectory in ./third_party.