platform_system_sepolicy/vendor
Yi-Yo Chiang 5854941f63 Add rules for calling ReadDefaultFstab()
Grant ReadDefaultFstab() callers
  allow scontext { metadata_file gsi_metadata_file_type }:dir search;
  allow scontext gsi_public_metadata_file:file r_file_perms;
so they can search / read DSU metadata files.
The DSU metadata files are required to deduce the correct fstab.

Also tighten the neverallow rules in gsid.te.

Bug: 181110285
Test: Build pass, presubmit test
Test: Boot and check avc denials
Test: Boot with DSU and check avc denials
Change-Id: Ie464b9a8f7a89f9cf8f4e217dad1322ba3ad0633
2021-03-29 15:23:29 +08:00
..
file.te
file_contexts Add CEC HAL 1.1 2021-02-15 09:36:55 +01:00
hal_atrace_default.te
hal_audio_default.te
hal_audiocontrol_default.te
hal_authsecret_default.te
hal_bluetooth_btlinux.te
hal_bluetooth_default.te
hal_bootctl_default.te Add rules for calling ReadDefaultFstab() 2021-03-29 15:23:29 +08:00
hal_broadcastradio_default.te
hal_camera_default.te Revert "Allow hal_face to write to /data/vendor/camera_calibration/*." 2019-06-19 20:15:50 +00:00
hal_can_socketcan.te Enable CAN HAL to scan /sys/devices for USB CAN 2020-03-17 12:10:07 -07:00
hal_cas_default.te
hal_configstore_default.te
hal_confirmationui_default.te
hal_contexthub_default.te
hal_drm_default.te Allow drm hals to access allocator hal 2020-04-13 20:01:06 +00:00
hal_dumpstate_default.te
hal_evs_default.te Update automotive display service rules 2020-02-29 11:01:26 -08:00
hal_face_default.te
hal_fingerprint_default.te
hal_gatekeeper_default.te
hal_gnss_default.te Add gnss_device dev_type 2020-03-17 20:25:51 +00:00
hal_graphics_allocator_default.te
hal_graphics_composer_default.te
hal_health_default.te
hal_health_storage_default.te
hal_identity_default.te Add SELinux policy for Identity Credential HAL 2020-01-14 20:13:39 -05:00
hal_input_classifier_default.te
hal_ir_default.te
hal_keymaster_default.te
hal_keymint_default.te The SE Policies to incorporate ISecureClock and ISharedSecret services along with IKeyMintDevice service into default keymint HAL Server. 2021-02-10 18:45:07 +00:00
hal_light_default.te
hal_lowpan_default.te
hal_memtrack_default.te
hal_nfc_default.te
hal_oemlock_default.te Add sepolicy for oemlock aidl HAL 2021-01-11 05:57:17 +00:00
hal_power_default.te
hal_power_stats_default.te
hal_radio_config_default.te
hal_radio_default.te
hal_rebootescrow_default.te rebootescrow: allow use of block file 2020-01-27 12:28:44 -08:00
hal_secure_element_default.te
hal_sensors_default.te Add missing permission for accessing the DMA-BUF system heap 2021-03-03 14:22:48 -08:00
hal_tetheroffload_default.te
hal_thermal_default.te
hal_tv_cec_default.te
hal_tv_input_default.te
hal_tv_tuner_default.te Allow tuner default implementation to access /dev/dma_heap/system 2021-03-02 15:21:45 -08:00
hal_usb_default.te
hal_usb_gadget_default.te Add sepolicy for usb gadget hal v1.1 2020-01-15 16:44:39 +08:00
hal_vehicle_default.te Revert "Revert "hal_can_*: use hal_attribute_service"" 2021-01-11 18:25:51 +00:00
hal_vibrator_default.te
hal_vr_default.te
hal_weaver_default.te Add sepolicy for weaver aidl HAL service 2021-01-22 06:34:41 +00:00
hal_wifi_default.te
hal_wifi_hostapd_default.te
hal_wifi_supplicant_default.te
keys.conf Copying platform seinfo into vendor partition 2020-06-04 17:27:15 +08:00
mac_permissions.xml Copying platform seinfo into vendor partition 2020-06-04 17:27:15 +08:00
mediacodec.te Allow mediacodec to allocate from the DMA-BUF system heap 2021-01-14 05:13:54 +00:00
rild.te
tee.te
vendor_install_recovery.te Moving recovery resources from /system to /vendor 2019-10-04 14:40:27 -07:00
vendor_misc_writer.te
vendor_modprobe.te modprobe: add -s/--syslog flag 2020-06-25 11:30:24 -07:00
vndservice_contexts Allow vndservicemanager to self-register. 2020-03-06 16:35:52 -08:00
vndservicemanager.te Allow vndservicemanager to self-register. 2020-03-06 16:35:52 -08:00