platform_system_sepolicy/public/mediaanalytics.te
Ray Essick 090f4a4d9f Allow access to mediaanalytics service
media framework analytics are gathered in a separate service.
define a context for this new service, allow various
media-related services and libraries to access this new service.

Bug: 30267133
Test: ran media CTS, watched for selinux denials.
Change-Id: I5aa5aaa5aa9e82465b8024f87ed32d6ba4db35ca
2016-12-03 00:06:20 +00:00

26 lines
785 B
Text

# mediaanalytics - daemon for collecting media analytics data
type mediaanalytics, domain;
type mediaanalytics_exec, exec_type, file_type;
binder_use(mediaanalytics)
binder_call(mediaanalytics, binderservicedomain)
binder_service(mediaanalytics)
allow mediaanalytics mediaanalytics_service:service_manager add;
allow mediaanalytics system_server:fd use;
r_dir_file(mediaanalytics, cgroup)
allow mediaanalytics proc_meminfo:file r_file_perms;
###
### neverallow rules
###
# mediaanalytics should never execute any executable without a
# domain transition
neverallow mediaanalytics { file_type fs_type }:file execute_no_trans;
# mediaanalytics should never need network access. Disallow network sockets.
neverallow mediaanalytics domain:{ tcp_socket udp_socket rawip_socket } *;