platform_system_sepolicy/private
Kevin Rocard 83f65ebbb2 Allow audioserver to access the package manager
This can not be done from the system server as there are native API that
do not go through it (aaudio, opensles).

Test: adb shell dumpsys media.audio_policy | grep -i 'Package manager'
Bug: 111453086
Signed-off-by: Kevin Rocard <krocard@google.com>
Change-Id: I0a4021f76b5937c6191859892fefaaf47b77967f
2019-02-28 01:50:22 +00:00
..
compat Decouple system_suspend from hal attributes. 2019-02-26 18:10:28 -08:00
access_vectors Update access_vectors 2018-11-01 19:53:50 -07:00
adbd.te adbd: do not audit vsock_socket create 2019-02-25 14:55:27 -08:00
apex_test_prepostinstall.te Sepolicy: Initial Apexd pre-/postinstall rules 2019-01-24 15:06:17 -08:00
apexd.te Allow apexd to reboot device 2019-02-26 13:29:22 +00:00
app.te Initial selinux policy support for memfd 2019-01-30 19:11:49 +00:00
app_neverallows.te Neverallow app open access to /dev/ashmem 2019-02-27 21:17:25 +00:00
app_zygote.te sepolicy for ashmemd 2019-02-05 21:38:14 +00:00
asan_extract.te
ashmemd.te sepolicy for ashmemd 2019-02-05 21:38:14 +00:00
atrace.te sepolicy: add rules for traced_probes to capture stderr and kill atrace on timeout 2018-11-16 14:47:19 +00:00
audioserver.te Allow audioserver to access the package manager 2019-02-28 01:50:22 +00:00
binder_in_vendor_violators.te
binderservicedomain.te
blank_screen.te Introduce system_file_type 2018-09-27 12:52:09 -07:00
blkid.te Introduce system_file_type 2018-09-27 12:52:09 -07:00
blkid_untrusted.te
bluetooth.te Fix permissions for bluetooth tethering. 2019-01-19 11:52:32 +09:00
bluetoothdomain.te
bootanim.te Dontaudit denials caused by race with labeling. 2018-02-14 17:07:13 -08:00
bootstat.te
bpfloader.te Add permissions for bpf.progs_loaded property 2019-01-14 10:59:10 -05:00
bufferhubd.te Remove unused bufferhub sepolicy 2018-12-10 13:36:11 -08:00
bug_map bug_map: remove tracking for b/79414024 2019-02-25 12:25:25 -08:00
cameraserver.te Allow cameraserver to access tmpfs 2019-01-30 05:31:42 +00:00
charger.te
clatd.te
coredomain.te sepolicy for ashmemd 2019-02-05 21:38:14 +00:00
cppreopts.te Sepolicy: Clean up moved files 2019-02-22 08:36:41 -08:00
crash_dump.te crash_dump: dontaudit gpu_device access 2019-02-18 21:06:42 +00:00
dex2oat.te Sepolicy: Move dex2oat and postinstall_dexopt to private 2019-02-26 13:13:45 -08:00
dexoptanalyzer.te Properly Treble-ize tmpfs access 2019-01-26 17:30:41 +00:00
dhcp.te
dnsmasq.te
domain.te Sepolicy: Move dac_override checks to private 2019-02-26 13:12:05 -08:00
drmserver.te
dumpstate.te Add incidentcompanion service. 2019-01-26 13:15:45 -08:00
ephemeral_app.te Neverallow app open access to /dev/ashmem 2019-02-27 21:17:25 +00:00
fastbootd.te Add sepolicy for fastbootd 2018-08-15 08:45:22 -07:00
file.te Add initial sepolicy for app data snapshots. 2019-01-16 15:22:51 +00:00
file_contexts Decouple system_suspend from hal attributes. 2019-02-26 18:10:28 -08:00
file_contexts_asan Label /data/asan/* libs as system_lib_file. 2018-10-10 11:23:00 -07:00
file_contexts_overlayfs fs_mgr: add /mnt/scratch to possible overlayfs support directories 2018-10-08 14:23:01 +00:00
fingerprintd.te
flags_health_check.te sepolicy for server configurable flags 2018-11-01 03:28:56 +00:00
fs_use fs_mgr: add overlayfs handling for squashfs system filesystems 2018-08-08 07:33:10 -07:00
fsck.te
fsck_untrusted.te
fwk_bufferhub.te Allow bufferhub service to allocate buffer 2018-11-07 13:57:55 -08:00
gatekeeperd.te
genfs_contexts Add sysfs_extcon for /sys/class/extcon 2019-02-21 17:16:34 +00:00
gpuservice.te Game Driver: sepolicy update for plumbing GpuStats into GpuService 2019-02-08 18:15:17 -08:00
gsid.te Add sepolicy for gsid properties, and allow system_server to read them. 2019-02-19 21:08:09 +00:00
hal_allocator_default.te sepolicy for ashmemd 2019-02-05 21:38:14 +00:00
halclientdomain.te
halserverdomain.te
healthd.te
heapprofd.te Allow heap profiling of certain app domains on user builds 2019-01-21 14:30:57 +00:00
hwservice_contexts Add Bluetooth Audio HAL interface V2 as hal_audio_hwservice 2019-01-14 22:26:22 +08:00
hwservicemanager.te Finer grained permissions for ctl. properties 2018-05-22 13:47:16 -07:00
idmap.te Add idmap2 and idmap2d 2018-11-15 14:42:10 +00:00
incident.te Introduce system_file_type 2018-09-27 12:52:09 -07:00
incident_helper.te Allow dumpstate to dump incidentd 2018-12-04 15:42:56 -08:00
incidentd.te Allow dumpstate to dump incidentd 2018-12-04 15:42:56 -08:00
init.te Allow executing bpfloader from init and modify rules 2019-01-14 10:59:10 -05:00
initial_sid_contexts
initial_sids
inputflinger.te
install_recovery.te
installd.te Allow installd to access device_config_runtime_native_boot_prop. 2019-02-26 08:56:57 +00:00
iorapd.te iorapd: add tmpfs type 2019-01-26 12:55:13 -08:00
isolated_app.te Neverallow app open access to /dev/ashmem 2019-02-27 21:17:25 +00:00
iw.te Allow iw to be run at init phase. 2018-11-14 19:10:12 +00:00
kernel.te
keys.conf sepolicy change for NetworkStack signature 2019-02-14 07:58:13 +09:00
keystore.te Allow Keystore to check security logging property. 2018-01-24 19:49:18 +00:00
llkd.te Add policy for apexd. 2018-10-04 07:06:45 +00:00
lmkd.te
logd.te Properly Treble-ize tmpfs access 2019-01-26 17:30:41 +00:00
logpersist.te
mac_permissions.xml sepolicy change for NetworkStack signature 2019-02-14 07:58:13 +09:00
mdnsd.te Introduce system_file_type 2018-09-27 12:52:09 -07:00
mediadrmserver.te
mediaextractor.te Initial selinux policy support for memfd 2019-01-30 19:11:49 +00:00
mediametrics.te
mediaprovider.te Neverallow app open access to /dev/ashmem 2019-02-27 21:17:25 +00:00
mediaserver.te Properly Treble-ize tmpfs access 2019-01-26 17:30:41 +00:00
mediaswcodec.te add mediaswcodec service 2018-10-11 15:10:17 -07:00
mini_keyctl.te add selinux rules for mini-keyctl 2019-01-31 15:12:11 -08:00
mls Initial selinux policy support for memfd 2019-01-30 19:11:49 +00:00
mls_decl
mls_macros
modprobe.te
mtp.te
netd.te Add NetworkStack policies for netd and netlink 2019-01-28 14:40:52 +09:00
netutils_wrapper.te Start the process of locking down proc/net 2018-05-04 21:36:33 +00:00
network_stack.te Add NetworkStack policies for netd and netlink 2019-01-28 14:40:52 +09:00
nfc.te SE Policy for Secure Element app and Secure Element HAL 2018-01-29 21:31:42 +00:00
notify_traceur.te Allow the init process to execute the notify_traceur.sh script 2019-02-07 00:28:40 +00:00
otapreopt_chroot.te Allow otapreopt to use bind-mounted Bionic artifacts from the Runtime APEX. 2019-01-31 19:09:08 +00:00
otapreopt_slot.te Sepolicy: Clean up moved files 2019-02-22 08:36:41 -08:00
perfetto.te Properly Treble-ize tmpfs access 2019-01-26 17:30:41 +00:00
performanced.te
perfprofd.te Decouple system_suspend from hal attributes. 2019-02-26 18:10:28 -08:00
platform_app.te Allowing sysui to access statsd. 2019-02-11 14:09:42 -08:00
policy_capabilities Add nnp_nosuid_transition policycap and related class/perm definitions. 2018-09-07 10:52:31 -07:00
port_contexts
postinstall.te
postinstall_dexopt.te Sepolicy: Move dex2oat and postinstall_dexopt to private 2019-02-26 13:13:45 -08:00
ppp.te
preloads_copy.te Add sepolicy for preloads_copy script 2018-10-23 17:11:36 +01:00
preopt2cachename.te Sepolicy: Clean up moved files 2019-02-22 08:36:41 -08:00
priv_app.te Game Driver: sepolicy update for plumbing GpuStats into GpuService 2019-02-08 18:15:17 -08:00
profman.te
property_contexts Add sepolicy for gsid properties, and allow system_server to read them. 2019-02-19 21:08:09 +00:00
racoon.te
radio.te Add label for time (zone) system properties 2018-06-25 17:59:56 +01:00
recovery.te
recovery_persist.te Properly Treble-ize tmpfs access 2019-01-26 17:30:41 +00:00
recovery_refresh.te Properly Treble-ize tmpfs access 2019-01-26 17:30:41 +00:00
roles_decl
rs.te rs: add tests to ensure rs cannot abuse app data 2019-01-17 15:24:34 -08:00
rss_hwm_reset.te SELinux policy for rss_hwm_reset 2018-12-15 10:13:03 +00:00
runas.te
runas_app.te allow runas_app untrusted_app_all:unix_stream_socket connectto 2019-02-08 11:35:50 -08:00
sdcardd.te
seapp_contexts sepolicy change for NetworkStack signature 2019-02-14 07:58:13 +09:00
secure_element.te SE Policy for Secure Element app and Secure Element HAL 2018-01-29 21:31:42 +00:00
security_classes Update access_vectors 2018-11-01 19:53:50 -07:00
service.te sepolicy for ashmemd 2019-02-05 21:38:14 +00:00
service_contexts Merge "Revert "sepolicy entries for time zone detector service"" 2019-02-06 10:15:23 -08:00
servicemanager.te
sgdisk.te
shared_relro.te
shell.te allow shell rs_exec:file rx_file_perms 2019-02-26 13:09:28 -08:00
simpleperf_app_runner.te Add sepolicy for simpleperf_app_runner. 2019-01-23 23:23:09 +00:00
slideshow.te
stats.te Allowing sysui to access statsd. 2019-02-11 14:09:42 -08:00
statsd.te Incidentd gets statsd incident section 2018-11-13 09:18:34 -08:00
storaged.te Introduce system_file_type 2018-09-27 12:52:09 -07:00
su.te SELinux policies for Perfetto cmdline client (/system/bin/perfetto) 2018-01-29 11:06:00 +00:00
surfaceflinger.te Initial selinux policy support for memfd 2019-01-30 19:11:49 +00:00
system_app.te Game Driver: sepolicy update for plumbing GpuStats into GpuService 2019-02-08 18:15:17 -08:00
system_server.te Decouple system_suspend from hal attributes. 2019-02-26 18:10:28 -08:00
system_server_startup.te Properly Treble-ize tmpfs access 2019-01-26 17:30:41 +00:00
system_suspend.te Decouple system_suspend from hal attributes. 2019-02-26 18:10:28 -08:00
technical_debt.cil Allow app to conntect to BufferHub service 2019-01-14 10:49:35 -08:00
thermalserviced.te Revert "Move thermal service into system_server" 2018-12-11 17:04:17 +00:00
tombstoned.te
toolbox.te
traced.te Allow traced to notify traceur via property 2019-02-06 08:47:04 +00:00
traced_probes.te Allow perfetto to ingest logs on userdebug/eng 2019-01-10 20:14:06 +00:00
traceur_app.te Allow the Traceur app to start Perfetto. 2018-12-10 18:51:29 -08:00
tzdatacheck.te
ueventd.te
uncrypt.te
untrusted_app.te Add untrusted_app_27 2018-04-03 12:25:51 -07:00
untrusted_app_25.te Neverallow app open access to /dev/ashmem 2019-02-27 21:17:25 +00:00
untrusted_app_27.te Neverallow app open access to /dev/ashmem 2019-02-27 21:17:25 +00:00
untrusted_app_all.te Neverallow app open access to /dev/ashmem 2019-02-27 21:17:25 +00:00
update_engine.te
update_engine_common.te
update_verifier.te
usbd.te
users
vdc.te
vendor_init.te Remove vendor_init from coredomain 2018-01-29 18:07:41 +00:00
viewcompiler.te Properly Treble-ize tmpfs access 2019-01-26 17:30:41 +00:00
virtual_touchpad.te
vold.te Abolish calls to shell in vold 2018-11-30 16:02:04 -08:00
vold_prepare_subdirs.te Add rules for multi-user backup/restore 2019-01-17 12:53:08 +00:00
vr_hwc.te
wait_for_keymaster.te Introduce system_file_type 2018-09-27 12:52:09 -07:00
watchdogd.te Move watchdogd out of init and into its own domain 2018-08-03 19:28:05 +00:00
webview_zygote.te sepolicy for ashmemd 2019-02-05 21:38:14 +00:00
wificond.te
wpantund.te
zygote.te Update a comment to match the latest rules. 2019-02-14 11:48:49 -08:00