platform_system_sepolicy/mediaextractor.te
Jeff Vander Stoep da6ecee0dc grant mediaextractor domain_deprecated attribute
Bug: 25433265
Change-Id: I6ad288fa25c61e3ac79f592d9a58e27a60f3d9cf
2015-11-06 13:10:38 -08:00

45 lines
1.3 KiB
Text

# mediaextractor - multimedia daemon
type mediaextractor, domain, domain_deprecated;
type mediaextractor_exec, exec_type, file_type;
typeattribute mediaextractor mlstrustedsubject;
init_daemon_domain(mediaextractor)
binder_use(mediaextractor)
binder_call(mediaextractor, binderservicedomain)
binder_call(mediaextractor, appdomain)
binder_service(mediaextractor)
# Required by Widevine DRM (b/22990512)
allow mediaextractor self:process execmem;
allow mediaextractor kernel:system module_request;
# Needed on some devices for playing DRM protected content,
# but seems expected and appropriate for all devices.
unix_socket_connect(mediaextractor, drmserver, drmserver)
allow mediaextractor drmserver_service:service_manager find;
allow mediaextractor mediaextractor_service:service_manager { add find };
allow mediaextractor processinfo_service:service_manager find;
use_drmservice(mediaextractor)
allow mediaextractor drmserver:drmservice {
consumeRights
setPlaybackStatus
openDecryptSession
closeDecryptSession
initializeDecryptUnit
decrypt
finalizeDecryptUnit
pread
};
###
### neverallow rules
###
# mediaextractor should never execute any executable without a
# domain transition
neverallow mediaextractor { file_type fs_type }:file execute_no_trans;