platform_system_sepolicy/vendor
Jeff Vander Stoep 639a2b842c Add default label and mapping for vendor services
Adding the default label/mapping is important because:
1.  Lookups of services without an selinux label should generate
    a denial.
2.  In permissive mode, lookups of a service without a label should be
    be allowed, without the default label service manager disallows
    access.
3.  We can neverallow use of the default label.

Bug: 37762790
Test: Build and flash policy onto Marlin with unlabeled vendor services.
    Add/find of unlabeled vendor services generate a denial.

Change-Id: I66531deedc3f9b79616f5d0681c87ed66aca5b80
2017-04-28 14:00:10 -07:00
..
file.te sepolicy: Move hostapd to vendor 2017-03-09 11:17:45 +08:00
file_contexts Merge "Add sepolicy for tv.cec" into oc-dev am: 976fb16bc1 2017-04-12 08:23:58 +00:00
hal_audio_default.te Fix typos in comment 2017-04-25 08:49:44 -07:00
hal_bluetooth_default.te sepolicy: make exec_types in /vendor a subset of vendor_file_type 2017-04-11 17:20:36 +00:00
hal_bootctl_default.te sepolicy: make exec_types in /vendor a subset of vendor_file_type 2017-04-11 17:20:36 +00:00
hal_camera_default.te Restrict access to hwservicemanager 2017-04-21 09:54:53 -07:00
hal_configstore_default.te sepolicy: make exec_types in /vendor a subset of vendor_file_type 2017-04-11 17:20:36 +00:00
hal_contexthub_default.te sepolicy: make exec_types in /vendor a subset of vendor_file_type 2017-04-11 17:20:36 +00:00
hal_drm_default.te Remove unnecessary attributes 2017-04-14 09:39:19 -07:00
hal_dumpstate_default.te sepolicy: make exec_types in /vendor a subset of vendor_file_type 2017-04-11 17:20:36 +00:00
hal_fingerprint_default.te Remove unnecessary attributes 2017-04-14 09:39:19 -07:00
hal_gatekeeper_default.te sepolicy: make exec_types in /vendor a subset of vendor_file_type 2017-04-11 17:20:36 +00:00
hal_gnss_default.te sepolicy: make exec_types in /vendor a subset of vendor_file_type 2017-04-11 17:20:36 +00:00
hal_graphics_allocator_default.te sepolicy: make exec_types in /vendor a subset of vendor_file_type 2017-04-11 17:20:36 +00:00
hal_graphics_composer_default.te sepolicy: make exec_types in /vendor a subset of vendor_file_type 2017-04-11 17:20:36 +00:00
hal_health_default.te sepolicy: make exec_types in /vendor a subset of vendor_file_type 2017-04-11 17:20:36 +00:00
hal_ir_default.te sepolicy: make exec_types in /vendor a subset of vendor_file_type 2017-04-11 17:20:36 +00:00
hal_keymaster_default.te sepolicy: make exec_types in /vendor a subset of vendor_file_type 2017-04-11 17:20:36 +00:00
hal_light_default.te sepolicy: make exec_types in /vendor a subset of vendor_file_type 2017-04-11 17:20:36 +00:00
hal_memtrack_default.te sepolicy: make exec_types in /vendor a subset of vendor_file_type 2017-04-11 17:20:36 +00:00
hal_nfc_default.te Add a TODO for the NFC HAL socket use violation 2017-04-24 14:37:53 -07:00
hal_omx.te mediacodec violates "no Binder in vendor" rule 2017-03-24 17:22:17 -07:00
hal_power_default.te sepolicy: make exec_types in /vendor a subset of vendor_file_type 2017-04-11 17:20:36 +00:00
hal_sensors_default.te Restrict access to hwservicemanager 2017-04-21 09:54:53 -07:00
hal_thermal_default.te sepolicy: make exec_types in /vendor a subset of vendor_file_type 2017-04-11 17:20:36 +00:00
hal_tv_cec_default.te Make hal_tv_cec_default exec a vendor_file_type 2017-04-13 17:32:43 -07:00
hal_tv_input_default.te sepolicy: make exec_types in /vendor a subset of vendor_file_type 2017-04-11 17:20:36 +00:00
hal_usb_default.te sepolicy: make exec_types in /vendor a subset of vendor_file_type 2017-04-11 17:20:36 +00:00
hal_vibrator_default.te sepolicy: make exec_types in /vendor a subset of vendor_file_type 2017-04-11 17:20:36 +00:00
hal_vr_default.te sepolicy: make exec_types in /vendor a subset of vendor_file_type 2017-04-11 17:20:36 +00:00
hal_wifi_default.te sepolicy: make exec_types in /vendor a subset of vendor_file_type 2017-04-11 17:20:36 +00:00
hal_wifi_offload_default.te label hal_wifi_offload to be vendor type 2017-04-15 19:07:12 -07:00
hal_wifi_supplicant_default.te Restrict access to hwservicemanager 2017-04-21 09:54:53 -07:00
hostapd.te Remove unnecessary attributes 2017-04-14 09:39:19 -07:00
rild.te sepolicy: make exec_types in /vendor a subset of vendor_file_type 2017-04-11 17:20:36 +00:00
tee.te Remove unnecessary attributes 2017-04-14 09:39:19 -07:00
vndservice_contexts Add default label and mapping for vendor services 2017-04-28 14:00:10 -07:00
vndservicemanager.te sepolicy: make exec_types in /vendor a subset of vendor_file_type 2017-04-11 17:20:36 +00:00