Add sepolicy for IpMemoryStoreService

Bug: 116512211
Test: Builds, boots, including upcoming changes needing this
Change-Id: I6f119368c5a4f7ac6c0325915dff60124c5a6399
This commit is contained in:
Chalard Jean 2018-12-05 14:47:51 +09:00
parent 0fa0d1e596
commit fb15c9f12f
8 changed files with 10 additions and 0 deletions

View file

@ -23,3 +23,6 @@ neverallow { appdomain -shell userdebug_or_eng(`-su') }
{ domain -appdomain -crash_dump -rs }:process { transition };
neverallow { appdomain -shell userdebug_or_eng(`-su') }
{ domain -appdomain }:process { dyntransition };
# Disallow apps from using IP memory store
neverallow { appdomain -shell } ipmemorystore_service:service_manager *;

View file

@ -102,6 +102,7 @@
iorapd_exec
iorapd_service
iorapd_tmpfs
ipmemorystore_service
kmsg_debug_device
last_boot_reason_prop
llkd

View file

@ -93,6 +93,7 @@
iorapd_exec
iorapd_service
iorapd_tmpfs
ipmemorystore_service
last_boot_reason_prop
llkd
llkd_exec

View file

@ -47,6 +47,7 @@
heapprofd_prop
heapprofd_socket
idmap_service
ipmemorystore_service
iris_service
iris_vendor_data_file
llkd

View file

@ -82,6 +82,7 @@ iphonesubinfo2 u:object_r:radio_service:s0
iphonesubinfo u:object_r:radio_service:s0
ims u:object_r:radio_service:s0
imms u:object_r:imms_service:s0
ipmemorystore u:object_r:ipmemorystore_service:s0
ipsec u:object_r:ipsec_service:s0
iris u:object_r:iris_service:s0
isms_msim u:object_r:radio_service:s0

View file

@ -74,6 +74,7 @@ allow system_app {
-dumpstate_service
-installd_service
-iorapd_service
-ipmemorystore_service
-netd_service
-virtual_touchpad_service
-vold_service

View file

@ -101,6 +101,7 @@ type hdmi_control_service, system_api_service, system_server_service, service_ma
type imms_service, app_api_service, ephemeral_app_api_service, system_server_service, service_manager_type;
type input_method_service, app_api_service, ephemeral_app_api_service, system_server_service, service_manager_type;
type input_service, app_api_service, ephemeral_app_api_service, system_server_service, service_manager_type;
type ipmemorystore_service, system_server_service, service_manager_type;
type ipsec_service, app_api_service, ephemeral_app_api_service, system_server_service, service_manager_type;
type iris_service, app_api_service, system_server_service, service_manager_type;
type jobscheduler_service, app_api_service, ephemeral_app_api_service, system_server_service, service_manager_type;

View file

@ -11,6 +11,7 @@ allow traceur_app {
-gatekeeper_service
-incident_service
-installd_service
-ipmemorystore_service
-iorapd_service
-netd_service
-virtual_touchpad_service