platform_system_sepolicy/private
Pavel Grafov 118e4969d2 Allow system apps to read log props.
This is needed to allow system apps to know whether security
logging is enabled, so that they can in this case log additional
audit events.

Test: logged a security event from locally modified KeyChain app.
Bug: 70886042
Change-Id: I9e18d59d72f40510f81d1840e4ac76a654cf6cbd
2018-01-18 17:22:28 +00:00
..
compat Add sepolicy to lock down bpf access 2018-01-17 23:19:30 +00:00
access_vectors sepolicy: New sepolicy classes and rules about bpf object 2018-01-02 11:52:33 -08:00
adbd.te Whitelist exported platform properties 2018-01-10 16:15:25 +00:00
app.te Allow More Apps to Recv UDP Sockets from SystemServer 2018-01-15 23:10:42 +00:00
app_neverallows.te Allow applications to use NN API HAL services 2018-01-16 13:50:37 -08:00
asan_extract.te Sepolicy: Add ASAN-Extract 2017-04-05 13:09:29 -07:00
atrace.te Sync internal master and AOSP sepolicy. 2017-09-26 14:38:47 -07:00
audioserver.te Allow audioserver to talk to bluetooth server 2017-04-28 20:02:48 +00:00
binder_in_vendor_violators.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
binderservicedomain.te Move binderservicedomain policy to private 2017-02-08 09:09:39 -08:00
blkid.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
blkid_untrusted.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
bluetooth.te sepolicy: Add rules for non-init namespaces 2017-11-21 08:34:32 -07:00
bluetoothdomain.te Move bluetoothdomain policy to private 2017-02-06 15:32:08 -08:00
bootanim.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
bootstat.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
bpfloader.te Add sepolicy to lock down bpf access 2018-01-17 23:19:30 +00:00
bufferhubd.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
bug_map Annotate denials 2018-01-16 19:47:36 -08:00
cameraserver.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
charger.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
clatd.te domain_deprecated is dead 2017-07-28 22:01:46 +00:00
coredomain.te Whitelist exported platform properties 2018-01-10 16:15:25 +00:00
cppreopts.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
crash_dump.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
dex2oat.te domain_deprecated is dead 2017-07-28 22:01:46 +00:00
dexoptanalyzer.te Don't allow dexoptanalyzer to open app_data_files 2017-11-02 10:45:09 -07:00
dhcp.te domain_deprecated is dead 2017-07-28 22:01:46 +00:00
dnsmasq.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
domain.te storaged: remove access to sysfs_type 2018-01-16 18:39:29 -08:00
drmserver.te Tighten restrictions on core <-> vendor socket comms 2017-03-31 09:17:54 -07:00
dumpstate.te Add window trace files SELinux policy rules 2017-11-17 17:17:36 +00:00
ephemeral_app.te Allow More Apps to Recv UDP Sockets from SystemServer 2018-01-15 23:10:42 +00:00
file.te Setting up SELinux policy for statsd and stats service 2017-12-19 01:41:48 +00:00
file_contexts Add sepolicy to lock down bpf access 2018-01-17 23:19:30 +00:00
file_contexts_asan /odm is another vendor partition that can be customied by ODMs 2017-12-15 19:07:58 +09:00
fingerprintd.te domain_deprecated is dead 2017-07-28 22:01:46 +00:00
fs_use Split general policy into public and private components. 2016-10-06 13:09:06 -07:00
fsck.te domain_deprecated is dead 2017-07-28 22:01:46 +00:00
fsck_untrusted.te domain_deprecated is dead 2017-07-28 22:01:46 +00:00
gatekeeperd.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
genfs_contexts relabel files in /proc/net/xt_qtaguid/ 2018-01-11 16:46:36 +00:00
hal_allocator_default.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
halclientdomain.te Restrict access to hwservicemanager 2017-04-21 09:54:53 -07:00
halserverdomain.te Allow hals to read hwservicemanager prop. 2017-03-23 01:50:50 +00:00
healthd.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
hwservice_contexts Add broadcast radio HAL 2.0 default implementation to the sepolicy. 2017-12-07 09:48:16 -08:00
hwservicemanager.te sepolicy for lazy starting HIDL services 2017-10-17 16:36:10 -07:00
idmap.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
incident.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
incidentd.te sepolicy: Add rules for non-init namespaces 2017-11-21 08:34:32 -07:00
init.te add vendor_init.te 2017-10-25 09:21:30 -07:00
initial_sid_contexts Split general policy into public and private components. 2016-10-06 13:09:06 -07:00
initial_sids Split general policy into public and private components. 2016-10-06 13:09:06 -07:00
inputflinger.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
install_recovery.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
installd.te domain_deprecated is dead 2017-07-28 22:01:46 +00:00
isolated_app.te Perfetto SELinux policies 2018-01-10 00:18:46 +00:00
kernel.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
keys.conf Split general policy into public and private components. 2016-10-06 13:09:06 -07:00
keystore.te Merge "domain_deprecated is dead" 2017-07-28 23:22:43 +00:00
lmkd.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
logd.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
logpersist.te sepolicy: Add rules for non-init namespaces 2017-11-21 08:34:32 -07:00
mac_permissions.xml Move MediaProvider to its own domain, add new MtpServer permissions 2016-12-12 11:05:33 -08:00
mdnsd.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
mediadrmserver.te update sepolicy for gralloc HAL 2017-03-30 14:43:35 -07:00
mediaextractor.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
mediametrics.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
mediaprovider.te Whitelist exported platform properties 2018-01-10 16:15:25 +00:00
mediaserver.te Restrict access to hwservicemanager 2017-04-21 09:54:53 -07:00
mls sepolicy: add version_policy tool and version non-platform policy. 2016-12-06 08:56:02 -08:00
mls_decl sepolicy: add version_policy tool and version non-platform policy. 2016-12-06 08:56:02 -08:00
mls_macros Split general policy into public and private components. 2016-10-06 13:09:06 -07:00
modprobe.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
mtp.te domain_deprecated is dead 2017-07-28 22:01:46 +00:00
net.te Move netdomain policy to private 2017-02-06 15:02:00 -08:00
netd.te Add sepolicy to lock down bpf access 2018-01-17 23:19:30 +00:00
netutils_wrapper.te sepolicy: Add rules for non-init namespaces 2017-11-21 08:34:32 -07:00
nfc.te Allow vendor apps to use surfaceflinger_service 2017-11-09 15:41:37 +00:00
otapreopt_chroot.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
otapreopt_slot.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
performanced.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
perfprofd.te domain_deprecated is dead 2017-07-28 22:01:46 +00:00
platform_app.te Allow More Apps to Recv UDP Sockets from SystemServer 2018-01-15 23:10:42 +00:00
policy_capabilities Define extended_socket_class policy capability and socket classes 2017-02-06 13:53:11 -05:00
port_contexts Split general policy into public and private components. 2016-10-06 13:09:06 -07:00
postinstall.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
postinstall_dexopt.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
ppp.te domain_deprecated is dead 2017-07-28 22:01:46 +00:00
preopt2cachename.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
priv_app.te Allow More Apps to Recv UDP Sockets from SystemServer 2018-01-15 23:10:42 +00:00
profman.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
property_contexts Fix TODOs of duplicate property names for prefix and exact matching 2018-01-16 22:41:04 +00:00
racoon.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
radio.te domain_deprecated is dead 2017-07-28 22:01:46 +00:00
recovery.te domain_deprecated is dead 2017-07-28 22:01:46 +00:00
recovery_persist.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
recovery_refresh.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
roles_decl sepolicy: add version_policy tool and version non-platform policy. 2016-12-06 08:56:02 -08:00
runas.te domain_deprecated is dead 2017-07-28 22:01:46 +00:00
sdcardd.te domain_deprecated is dead 2017-07-28 22:01:46 +00:00
seapp_contexts Adding a traceur_app domain to remove it from shell 2018-01-02 15:29:03 -08:00
security_classes sepolicy: New sepolicy classes and rules about bpf object 2018-01-02 11:52:33 -08:00
service.te Setting up SELinux policy for statsd and stats service 2017-12-19 01:41:48 +00:00
service_contexts Add EuiccCardManager and EuiccCardController. 2018-01-11 10:32:47 -08:00
servicemanager.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
sgdisk.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
shared_relro.te domain_deprecated is dead 2017-07-28 22:01:46 +00:00
shell.te Allow shell to start vendor shell 2018-01-16 18:28:51 +00:00
slideshow.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
stats.te Setting up SELinux policy for statsd and stats service 2017-12-19 01:41:48 +00:00
statsd.te Update statsd sepolicies to avoid selinux violations during cts tests 2018-01-10 08:32:24 +00:00
storaged.te storaged: remove access to sysfs_type 2018-01-16 18:39:29 -08:00
su.te whitespace fix. 2017-11-01 10:17:39 -07:00
surfaceflinger.te Whitelist exported platform properties 2018-01-10 16:15:25 +00:00
system_app.te Allow system apps to read log props. 2018-01-18 17:22:28 +00:00
system_server.te Fix TODOs of duplicate property names for prefix and exact matching 2018-01-16 22:41:04 +00:00
technical_debt.cil Allow applications to use NN API HAL services 2018-01-16 13:50:37 -08:00
thermalserviced.te Sync internal master and AOSP sepolicy. 2017-09-26 14:38:47 -07:00
tombstoned.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
toolbox.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
traced.te Perfetto SELinux policies 2018-01-10 00:18:46 +00:00
traced_probes.te Perfetto SELinux policies 2018-01-10 00:18:46 +00:00
traceur_app.te Adding a traceur_app domain to remove it from shell 2018-01-02 15:29:03 -08:00
tzdatacheck.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
ueventd.te domain_deprecated is dead 2017-07-28 22:01:46 +00:00
uncrypt.te domain_deprecated is dead 2017-07-28 22:01:46 +00:00
untrusted_app.te Allow More Apps to Recv UDP Sockets from SystemServer 2018-01-15 23:10:42 +00:00
untrusted_app_25.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
untrusted_app_all.te Allow More Apps to Recv UDP Sockets from SystemServer 2018-01-15 23:10:42 +00:00
untrusted_v2_app.te Perfetto SELinux policies 2018-01-10 00:18:46 +00:00
update_engine.te domain_deprecated is dead 2017-07-28 22:01:46 +00:00
update_engine_common.te Split general policy into public and private components. 2016-10-06 13:09:06 -07:00
update_verifier.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
users Split general policy into public and private components. 2016-10-06 13:09:06 -07:00
vdc.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
vendor_init.te Copy a dontaudit from init to vendor_init 2017-11-15 14:57:14 -08:00
virtual_touchpad.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
vold.te domain_deprecated is dead 2017-07-28 22:01:46 +00:00
vold_prepare_subdirs.te vold_prepare_subdirs: grant chown 2018-01-10 08:37:42 -08:00
vr_hwc.te Restrict access to hwservicemanager 2017-04-21 09:54:53 -07:00
watchdogd.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
webview_zygote.te Fix permission typo 2018-01-03 08:46:05 -08:00
wificond.te SE Policy for Wifi Offload HAL 2017-05-18 09:49:55 -07:00
wpantund.te lowpan: Add wpantund to SEPolicy 2017-10-16 14:10:40 -07:00
zygote.te Whitelist exported platform properties 2018-01-10 16:15:25 +00:00