From 6970fafb37633473ffe39a2e18c053398bf565d6 Mon Sep 17 00:00:00 2001 From: Daniel Micay Date: Wed, 25 Jan 2023 07:32:55 -0500 Subject: [PATCH] defer SELinux policy changes for Vanadium --- static/releases.html | 1 - 1 file changed, 1 deletion(-) diff --git a/static/releases.html b/static/releases.html index 2b810740..80f58314 100644 --- a/static/releases.html +++ b/static/releases.html @@ -692,7 +692,6 @@
  • Apps: update to version 13
  • add GrapheneOS fs-verity public key as a supported key
  • require fs-verity for system app updates
  • -
  • SELinux policy: drop base OS apk_data_file restrictions to avoid blocking out-of-band updates to system apps providing native libraries such as Vanadium since we're going to be taking the approach of enforcing fs-verity for system app updates as a complete approach to proper verified boot enforcement for every read of data from out-of-band system component updates instead of only disallowing some forms of out-of-band updates
  • Vanadium: update Chromium base to 109.0.5414.118
  • SettingsIntelligence: drop no longer required QUERY_ALL_PACKAGES permission now that more precise queries are defined upstream providing the necessary package visibility for Settings app search