platform_system_sepolicy/prebuilts/api/29.0/private
Martijn Coenen 4c386e10c9 Don't give uid-based categories to app_zygote and isolated processes.
The mapping of UIDs to categories can only take 16 bits, yet isolated
processes start at UID 90000. Additionally, the main purpose of these
categories was to isolate app-private storage, but since isolated
processes don't have access to app-private storage anyway, removing them
doesn't hurt.

The upside is that this allows us to remove mIstrustedsubject from the
app_zygote domain, which prevents app code running in that context from
assigning itself arbitrary categories.

Bug: 157598026
Test: inspect categories of app_zygote and children; verify Chrome works
Merged-In: Idfa8625d939cf30f3683436949bb4f335851622a
Merged-In: I608a096cecffc1c1ff837611ca500a8da3cf1320
Change-Id: I608a096cecffc1c1ff837611ca500a8da3cf1320
2020-06-10 11:56:35 +00:00
..
compat Add persist.sys.theme. 2019-06-17 10:48:21 -07:00
access_vectors SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
adbd.te Allow adb forward to traced consumer socket 2020-01-10 09:17:27 -08:00
apex_test_prepostinstall.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
apexd.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
app.te Prevent apps from causing presubmit failures 2020-03-12 08:38:05 +00:00
app_neverallows.te Properly define hal_codec2 and related policies 2019-05-23 03:53:47 -07:00
app_zygote.te Don't give uid-based categories to app_zygote and isolated processes. 2020-06-10 11:56:35 +00:00
art_apex_boot_integrity.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
art_apex_postinstall.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
art_apex_preinstall.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
asan_extract.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
ashmemd.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
atrace.te atrace: debug: allow notifying camera HAL of a change in sysprops 2019-05-19 16:50:59 +01:00
audioserver.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
auditctl.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
binder_in_vendor_violators.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
binderservicedomain.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
blank_screen.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
blkid.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
blkid_untrusted.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
bluetooth.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
bluetoothdomain.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
bootanim.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
bootstat.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
bpfloader.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
bufferhubd.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
bug_map SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
cameraserver.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
charger.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
clatd.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
coredomain.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
cppreopts.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
crash_dump.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
dex2oat.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
dexoptanalyzer.te Allow dexoptanalyzer to mmap files with Linux 4.14+ that it can already access. 2019-09-13 13:45:40 +01:00
dhcp.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
dnsmasq.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
domain.te Allow rule to let settings access apex files 2019-06-27 11:32:49 -07:00
drmserver.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
dumpstate.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
ephemeral_app.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
fastbootd.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
file.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
file_contexts sepolicy: Add policy for migrate_legacy_obb_data.sh 2019-05-23 17:26:08 +01:00
file_contexts_asan SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
file_contexts_overlayfs SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
fingerprintd.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
flags_health_check.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
fs_use SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
fsck.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
fsck_untrusted.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
fsverity_init.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
fwk_bufferhub.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
gatekeeperd.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
genfs_contexts Allow Traceur to record the suspend_resume trace event 2019-08-13 17:13:00 +00:00
gpuservice.te Revert "Revert "Allow dumpstate to dumpsys gpu"" 2020-01-09 18:51:24 -08:00
gsid.te Allow init to mkdir inside /data/gsi. 2019-05-28 13:42:42 -07:00
hal_allocator_default.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
halclientdomain.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
halserverdomain.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
healthd.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
heapprofd.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
hwservice_contexts SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
hwservicemanager.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
idmap.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
incident.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
incident_helper.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
incidentd.te Add rules to dump hal traces 2019-06-19 19:55:14 +00:00
init.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
initial_sid_contexts SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
initial_sids SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
inputflinger.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
install_recovery.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
installd.te sepolicy: Add policy for migrate_legacy_obb_data.sh 2019-05-23 17:26:08 +01:00
iorapd.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
isolated_app.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
iw.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
kernel.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
keys.conf SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
keystore.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
llkd.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
lmkd.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
logd.te In native coverage builds, allow all domains to access /data/misc/trace 2019-06-19 16:27:17 -07:00
logpersist.te In native coverage builds, allow all domains to access /data/misc/trace 2019-06-19 16:27:17 -07:00
lpdumpd.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
mac_permissions.xml SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
mdnsd.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
mediadrmserver.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
mediaextractor.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
mediametrics.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
mediaprovider.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
mediaserver.te Properly define hal_codec2 and related policies 2019-05-23 03:53:47 -07:00
mediaswcodec.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
migrate_legacy_obb_data.te sepolicy: Adjust policy for migrate_legacy_obb_data.sh 2019-07-12 16:35:20 -07:00
mls SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
mls_decl SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
mls_macros SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
modprobe.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
mtp.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
netd.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
netutils_wrapper.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
network_stack.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
nfc.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
notify_traceur.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
otapreopt_chroot.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
otapreopt_slot.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
perfetto.te In native coverage builds, allow all domains to access /data/misc/trace 2019-06-19 16:27:17 -07:00
performanced.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
perfprofd.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
platform_app.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
policy_capabilities SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
port_contexts SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
postinstall.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
postinstall_dexopt.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
ppp.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
preloads_copy.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
preopt2cachename.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
priv_app.te Prevent apps from causing presubmit failures 2020-03-12 08:38:05 +00:00
profman.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
property_contexts Update Q sepolicy prebuilt 2020-02-11 13:53:22 +08:00
racoon.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
radio.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
recovery.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
recovery_persist.te In native coverage builds, allow all domains to access /data/misc/trace 2019-06-19 16:27:17 -07:00
recovery_refresh.te In native coverage builds, allow all domains to access /data/misc/trace 2019-06-19 16:27:17 -07:00
roles_decl SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
rs.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
rss_hwm_reset.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
runas.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
runas_app.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
sdcardd.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
seapp_contexts Don't give uid-based categories to app_zygote and isolated processes. 2020-06-10 11:56:35 +00:00
secure_element.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
security_classes SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
service.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
service_contexts SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
servicemanager.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
sgdisk.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
shared_relro.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
shell.te Allow shell to unlink perfetto_traces_data_file. 2019-10-29 10:32:35 +00:00
simpleperf_app_runner.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
slideshow.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
stats.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
statsd.te Allows StatsCompanionService to pipe data to statsd. 2019-05-23 20:35:34 +00:00
storaged.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
su.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
surfaceflinger.te Properly define hal_codec2 and related policies 2019-05-23 03:53:47 -07:00
system_app.te Allow rule to let settings access apex files 2019-06-27 11:32:49 -07:00
system_server.te system_server: TelephonyManager reads /proc/cmdline 2020-01-15 13:43:33 -08:00
system_server_startup.te system_server_startup: allow SIGCHLD to zygote 2019-06-14 16:56:05 -07:00
system_suspend.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
technical_debt.cil Properly define hal_codec2 and related policies 2019-05-23 03:53:47 -07:00
tombstoned.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
toolbox.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
traced.te In native coverage builds, allow all domains to access /data/misc/trace 2019-06-19 16:27:17 -07:00
traced_probes.te In native coverage builds, allow all domains to access /data/misc/trace 2019-06-19 16:27:17 -07:00
traceur_app.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
tzdatacheck.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
ueventd.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
uncrypt.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
untrusted_app.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
untrusted_app_25.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
untrusted_app_27.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
untrusted_app_all.te Prevent apps from causing presubmit failures 2020-03-12 08:38:05 +00:00
update_engine.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
update_engine_common.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
update_verifier.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
usbd.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
users SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
vdc.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
vendor_init.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
viewcompiler.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
virtual_touchpad.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
vold.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
vold_prepare_subdirs.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
vr_hwc.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
wait_for_keymaster.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
watchdogd.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
webview_zygote.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
wificond.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
wpantund.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00
zygote.te SEPolicy Prebuilts for Q 2019-05-14 21:42:22 -07:00