Merge "Further refined service_manager auditallow statements."

This commit is contained in:
Nick Kralevich 2014-07-18 17:58:05 +00:00 committed by Gerrit Code Review
commit 958ef56396
7 changed files with 30 additions and 2 deletions

View file

@ -54,6 +54,7 @@ service_manager_local_audit_domain(bluetooth)
auditallow bluetooth {
service_manager_type
-bluetooth_service
-radio_service
-system_server_service
}:service_manager find;

View file

@ -49,4 +49,8 @@ allow drmserver drmserver_service:service_manager add;
# Audited locally.
service_manager_local_audit_domain(drmserver)
auditallow drmserver { service_manager_type -drmserver_service }:service_manager find;
auditallow drmserver {
service_manager_type
-drmserver_service
-system_server_service
}:service_manager find;

View file

@ -96,3 +96,18 @@ control_logd(dumpstate)
# Read network state info files.
allow dumpstate net_data_file:dir search;
allow dumpstate net_data_file:file r_file_perms;
service_manager_local_audit_domain(dumpstate)
auditallow dumpstate {
service_manager_type
-drmserver_service
-healthd_service
-inputflinger_service
-keystore_service
-mediaserver_service
-nfc_service
-radio_service
-surfaceflinger_service
-system_app_service
-system_server_service
}:service_manager find;

View file

@ -21,4 +21,9 @@ allow isolated_app app_data_file:file execute;
# Audited locally.
service_manager_local_audit_domain(isolated_app)
auditallow isolated_app service_manager_type:service_manager find;
auditallow isolated_app {
service_manager_type
-radio_service
-surfaceflinger_service
-system_server_service
}:service_manager find;

1
nfc.te
View file

@ -21,5 +21,6 @@ service_manager_local_audit_domain(nfc)
auditallow nfc {
service_manager_type
-mediaserver_service
-surfaceflinger_service
-system_server_service
}:service_manager find;

View file

@ -35,5 +35,6 @@ auditallow radio {
service_manager_type
-mediaserver_service
-radio_service
-surfaceflinger_service
-system_server_service
}:service_manager find;

View file

@ -69,6 +69,7 @@ service_manager_local_audit_domain(untrusted_app)
auditallow untrusted_app {
service_manager_type
-drmserver_service
-keystore_service
-mediaserver_service
-nfc_service
-radio_service