platform_system_sepolicy/private
Tom Cherry 9c778045b2 Remove vendor_init from coredomain
vendor_init exists on the system partition, but it is meant to be an
extention of init that runs with vendor permissions for executing
vendor scripts, therefore it is not meant to be in coredomain.

Bug: 62875318
Test: boot walleye
Merged-In: I01af5c9f8b198674b15b90620d02725a6e7c1da6
Change-Id: I01af5c9f8b198674b15b90620d02725a6e7c1da6
2018-01-29 18:07:41 +00:00
..
compat Merge "sepolicy: restrict access to uid_cpupower files" 2018-01-24 19:05:40 +00:00
access_vectors sepolicy: New sepolicy classes and rules about bpf object 2018-01-02 11:52:33 -08:00
adbd.te Adding write permissions to traceur 2018-01-22 21:06:36 +00:00
app.te Allow More Apps to Recv UDP Sockets from SystemServer 2018-01-15 23:10:42 +00:00
app_neverallows.te Added default policy for Confirmation UI HAL 2018-01-24 10:22:40 -08:00
asan_extract.te Sepolicy: Add ASAN-Extract 2017-04-05 13:09:29 -07:00
atrace.te Sync internal master and AOSP sepolicy. 2017-09-26 14:38:47 -07:00
audioserver.te Don't record audio if UID is idle - sepolicy 2018-01-16 21:22:18 -08:00
binder_in_vendor_violators.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
binderservicedomain.te
blank_screen.te Add policy for 'blank_screen'. 2018-01-22 20:27:01 +00:00
blkid.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
blkid_untrusted.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
bluetooth.te sepolicy: Add rules for non-init namespaces 2017-11-21 08:34:32 -07:00
bluetoothdomain.te
bootanim.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
bootstat.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
bpfloader.te Add sepolicy to lock down bpf access 2018-01-17 23:19:30 +00:00
bufferhubd.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
bug_map Track crash_dump selinux denial. 2018-01-25 14:14:24 -08:00
cameraserver.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
charger.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
clatd.te domain_deprecated is dead 2017-07-28 22:01:46 +00:00
coredomain.te Remove vendor_init from coredomain 2018-01-29 18:07:41 +00:00
cppreopts.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
crash_dump.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
dex2oat.te domain_deprecated is dead 2017-07-28 22:01:46 +00:00
dexoptanalyzer.te Don't allow dexoptanalyzer to open app_data_files 2017-11-02 10:45:09 -07:00
dhcp.te domain_deprecated is dead 2017-07-28 22:01:46 +00:00
dnsmasq.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
domain.te Remove vendor_init from coredomain 2018-01-29 18:07:41 +00:00
drmserver.te Tighten restrictions on core <-> vendor socket comms 2017-03-31 09:17:54 -07:00
dumpstate.te Sepolicy: Allow stack dumps of statsd 2018-01-25 09:31:19 -08:00
e2fs.te Allow access to the metadata partition for metadata encryption. 2018-01-19 14:45:08 -08:00
ephemeral_app.te Allow More Apps to Recv UDP Sockets from SystemServer 2018-01-15 23:10:42 +00:00
file.te Setting up SELinux policy for statsd and stats service 2017-12-19 01:41:48 +00:00
file_contexts Add a default rule for /product files 2018-01-25 07:59:23 +09:00
file_contexts_asan /odm is another vendor partition that can be customied by ODMs 2017-12-15 19:07:58 +09:00
fingerprintd.te domain_deprecated is dead 2017-07-28 22:01:46 +00:00
fs_use
fsck.te Allow access to the metadata partition for metadata encryption. 2018-01-19 14:45:08 -08:00
fsck_untrusted.te domain_deprecated is dead 2017-07-28 22:01:46 +00:00
gatekeeperd.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
genfs_contexts sepolicy: restrict access to uid_cpupower files 2018-01-24 08:39:09 -08:00
hal_allocator_default.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
halclientdomain.te Restrict access to hwservicemanager 2017-04-21 09:54:53 -07:00
halserverdomain.te Allow hals to read hwservicemanager prop. 2017-03-23 01:50:50 +00:00
healthd.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
hwservice_contexts Add sepolicy for radio.config 2018-01-24 12:13:10 -08:00
hwservicemanager.te sepolicy for lazy starting HIDL services 2017-10-17 16:36:10 -07:00
idmap.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
incident.te Selinux permissions for incidentd project 2018-01-23 19:08:49 +00:00
incident_helper.te Selinux permissions for incidentd project 2018-01-23 19:08:49 +00:00
incidentd.te Update sepolicy of statsd to be able to find incident_service 2018-01-24 18:25:04 +00:00
init.te add vendor_init.te 2017-10-25 09:21:30 -07:00
initial_sid_contexts
initial_sids
inputflinger.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
install_recovery.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
installd.te domain_deprecated is dead 2017-07-28 22:01:46 +00:00
isolated_app.te Perfetto SELinux policies 2018-01-10 00:18:46 +00:00
kernel.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
keys.conf
keystore.te Added default policy for Confirmation UI HAL 2018-01-24 10:22:40 -08:00
lmkd.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
logd.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
logpersist.te sepolicy: Add rules for non-init namespaces 2017-11-21 08:34:32 -07:00
mac_permissions.xml
mdnsd.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
mediadrmserver.te update sepolicy for gralloc HAL 2017-03-30 14:43:35 -07:00
mediaextractor.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
mediametrics.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
mediaprovider.te Whitelist exported platform properties 2018-01-10 16:15:25 +00:00
mediaserver.te Restrict access to hwservicemanager 2017-04-21 09:54:53 -07:00
mls
mls_decl
mls_macros
modprobe.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
mtp.te domain_deprecated is dead 2017-07-28 22:01:46 +00:00
net.te
netd.te Add sepolicy to lock down bpf access 2018-01-17 23:19:30 +00:00
netutils_wrapper.te sepolicy: Add rules for non-init namespaces 2017-11-21 08:34:32 -07:00
nfc.te Allow vendor apps to use surfaceflinger_service 2017-11-09 15:41:37 +00:00
otapreopt_chroot.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
otapreopt_slot.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
performanced.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
perfprofd.te domain_deprecated is dead 2017-07-28 22:01:46 +00:00
platform_app.te Remove proc and sysfs access from system_app and platform_app. 2018-01-20 01:05:21 +00:00
policy_capabilities
port_contexts
postinstall.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
postinstall_dexopt.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
ppp.te domain_deprecated is dead 2017-07-28 22:01:46 +00:00
preopt2cachename.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
priv_app.te priv_app: remove access to 'proc' and 'sysfs' types. 2018-01-20 01:05:56 +00:00
profman.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
property_contexts Add default namespaces of odm properties 2018-01-18 13:31:37 +09:00
racoon.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
radio.te domain_deprecated is dead 2017-07-28 22:01:46 +00:00
recovery.te domain_deprecated is dead 2017-07-28 22:01:46 +00:00
recovery_persist.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
recovery_refresh.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
roles_decl
runas.te domain_deprecated is dead 2017-07-28 22:01:46 +00:00
sdcardd.te domain_deprecated is dead 2017-07-28 22:01:46 +00:00
seapp_contexts Adding a traceur_app domain to remove it from shell 2018-01-02 15:29:03 -08:00
security_classes sepolicy: New sepolicy classes and rules about bpf object 2018-01-02 11:52:33 -08:00
service.te Setting up SELinux policy for statsd and stats service 2017-12-19 01:41:48 +00:00
service_contexts Allow mediaextractor to load libraries from apk_data_file 2018-01-23 11:21:11 -08:00
servicemanager.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
sgdisk.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
shared_relro.te domain_deprecated is dead 2017-07-28 22:01:46 +00:00
shell.te Allow shell to start vendor shell 2018-01-16 18:28:51 +00:00
slideshow.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
stats.te Setting up SELinux policy for statsd and stats service 2017-12-19 01:41:48 +00:00
statsd.te Neverallow vendor_init from accessing stats_data_file 2018-01-25 19:42:11 +00:00
storaged.te storaged: remove access to sysfs_type 2018-01-16 18:39:29 -08:00
su.te whitespace fix. 2017-11-01 10:17:39 -07:00
surfaceflinger.te Whitelist exported platform properties 2018-01-10 16:15:25 +00:00
system_app.te Remove proc and sysfs access from system_app and platform_app. 2018-01-20 01:05:21 +00:00
system_server.te Sepolicy: Allow stack dumps of statsd 2018-01-25 09:31:19 -08:00
technical_debt.cil Allow applications to use NN API HAL services 2018-01-16 13:50:37 -08:00
thermalserviced.te Sync internal master and AOSP sepolicy. 2017-09-26 14:38:47 -07:00
tombstoned.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
toolbox.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
traced.te Perfetto SELinux policies 2018-01-10 00:18:46 +00:00
traced_probes.te Perfetto SELinux policies 2018-01-10 00:18:46 +00:00
traceur_app.te Fixing traceur selinux permission error 2018-01-22 19:59:35 -08:00
tzdatacheck.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
ueventd.te domain_deprecated is dead 2017-07-28 22:01:46 +00:00
uncrypt.te domain_deprecated is dead 2017-07-28 22:01:46 +00:00
untrusted_app.te Allow More Apps to Recv UDP Sockets from SystemServer 2018-01-15 23:10:42 +00:00
untrusted_app_25.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
untrusted_app_all.te Adding permission for traceur to use content provider 2018-01-24 10:17:00 -08:00
untrusted_v2_app.te Perfetto SELinux policies 2018-01-10 00:18:46 +00:00
update_engine.te domain_deprecated is dead 2017-07-28 22:01:46 +00:00
update_engine_common.te
update_verifier.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
usbd.te usbd sepolicy 2018-01-20 03:41:21 +00:00
users
vdc.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
vendor_init.te Remove vendor_init from coredomain 2018-01-29 18:07:41 +00:00
virtual_touchpad.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
vold.te domain_deprecated is dead 2017-07-28 22:01:46 +00:00
vold_prepare_subdirs.te vold_prepare_subdirs: grant chown 2018-01-10 08:37:42 -08:00
vr_hwc.te Restrict access to hwservicemanager 2017-04-21 09:54:53 -07:00
watchdogd.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
webview_zygote.te Fix permission typo 2018-01-03 08:46:05 -08:00
wificond.te SE Policy for Wifi Offload HAL 2017-05-18 09:49:55 -07:00
wpantund.te lowpan: Add wpantund to SEPolicy 2017-10-16 14:10:40 -07:00
zygote.te Whitelist exported platform properties 2018-01-10 16:15:25 +00:00