2017-04-11 01:57:48 +02:00
|
|
|
###
|
|
|
|
### A domain for android.process.media, which contains both
|
|
|
|
### MediaProvider and DownloadProvider and associated services.
|
|
|
|
###
|
|
|
|
|
|
|
|
typeattribute mediaprovider coredomain;
|
|
|
|
app_domain(mediaprovider)
|
|
|
|
|
|
|
|
# DownloadProvider accesses the network.
|
|
|
|
net_domain(mediaprovider)
|
|
|
|
|
|
|
|
# DownloadProvider uses /cache.
|
|
|
|
allow mediaprovider cache_file:dir create_dir_perms;
|
|
|
|
allow mediaprovider cache_file:file create_file_perms;
|
|
|
|
# /cache is a symlink to /data/cache on some devices. Allow reading the link.
|
|
|
|
allow mediaprovider cache_file:lnk_file r_file_perms;
|
2017-06-27 01:58:51 +02:00
|
|
|
# mediaprovider searches through /cache looking for orphans
|
|
|
|
# Ignore denials to /cache/recovery and /cache/backup.
|
|
|
|
dontaudit mediaprovider cache_private_backup_file:dir getattr;
|
|
|
|
dontaudit mediaprovider cache_recovery_file:dir getattr;
|
|
|
|
|
2018-05-12 03:35:55 +02:00
|
|
|
# Access external sdcards through /mnt/media_rw
|
|
|
|
allow mediaprovider { mnt_media_rw_file }:dir search;
|
2017-04-11 01:57:48 +02:00
|
|
|
|
|
|
|
allow mediaprovider app_api_service:service_manager find;
|
|
|
|
allow mediaprovider audioserver_service:service_manager find;
|
2021-04-15 03:41:28 +02:00
|
|
|
allow mediaprovider cameraserver_service:service_manager find;
|
2017-04-26 19:18:30 +02:00
|
|
|
allow mediaprovider drmserver_service:service_manager find;
|
2018-03-16 23:52:15 +01:00
|
|
|
allow mediaprovider mediaextractor_service:service_manager find;
|
2017-04-11 01:57:48 +02:00
|
|
|
allow mediaprovider mediaserver_service:service_manager find;
|
|
|
|
|
|
|
|
# Allow MediaProvider to read/write cached ringtones (opened by system).
|
|
|
|
allow mediaprovider ringtone_file:file { getattr read write };
|
|
|
|
|
|
|
|
# MtpServer uses /dev/mtp_usb
|
|
|
|
allow mediaprovider mtp_device:chr_file rw_file_perms;
|
|
|
|
|
|
|
|
# MtpServer uses /dev/usb-ffs/mtp
|
|
|
|
allow mediaprovider functionfs:dir search;
|
|
|
|
allow mediaprovider functionfs:file rw_file_perms;
|
2018-10-17 19:13:25 +02:00
|
|
|
allowxperm mediaprovider functionfs:file ioctl FUNCTIONFS_ENDPOINT_DESC;
|
2021-07-12 09:53:54 +02:00
|
|
|
allowxperm mediaprovider functionfs:file ioctl FUNCTIONFS_ENDPOINT_ALLOC;
|
2017-04-11 01:57:48 +02:00
|
|
|
|
|
|
|
# MtpServer sets sys.usb.ffs.mtp.ready
|
2020-04-27 16:49:15 +02:00
|
|
|
get_prop(mediaprovider, ffs_config_prop)
|
|
|
|
set_prop(mediaprovider, ffs_control_prop)
|
2021-03-09 11:09:06 +01:00
|
|
|
|
|
|
|
# DownloadManager may retrieve DRM status
|
|
|
|
get_prop(mediaprovider, drm_service_config_prop)
|