platform_system_sepolicy/private
Josh Gao b9c7001837 adbd should be able to shutdown shell:unix_stream_socket
adbd started calling shutdown and waiting for EOF before closing
sockets in commit 74b7ec72, because closing a TCP socket while you have
pending data to read is specified to send a TCP RST to the other end,
which can result in data that we've written into the socket to be
prematurely thrown away on the other end. Not being able to do so on a
Unix domain socket is benign, aside from the denial showing up in the
log.

Fixes the following selinux denial when installing a package:

  avc: denied { shutdown } for scontext=u:r:adbd:s0 tcontext=u:r:shell:s0 tclass=unix_stream_socket permissive=0

Test: manual
Change-Id: I266092a8323ac02bfe96738a8f4a8021f3a10387
2020-02-05 17:24:46 -08:00
..
compat Merge "snapshotctl better logging" 2020-02-04 22:18:33 +00:00
access_vectors Merge "access_vectors: remove flow_in and flow_out permissions from packet class" 2020-01-19 14:17:58 +00:00
adbd.te adbd should be able to shutdown shell:unix_stream_socket 2020-02-05 17:24:46 -08:00
aidl_lazy_test_server.te Add aidl_lazy_test_server 2020-01-07 15:11:03 -08:00
apex_test_prepostinstall.te Sepolicy: Initial Apexd pre-/postinstall rules 2019-01-24 15:06:17 -08:00
apexd.te Add dac_read_search to apexd to prevent spurious denials. 2020-01-30 19:06:30 +00:00
app.te Prevent apps from causing presubmit failures 2019-12-16 11:19:05 +01:00
app_neverallows.te Create new mediaprovider_app domain. 2020-02-04 16:53:18 +01:00
app_zygote.te debug builds: allow perf profiling of most domains 2020-01-22 22:04:02 +00:00
art_apex_boot_integrity.te Sepolicy: Allow everyone to search keyrings 2019-03-14 13:21:07 -07:00
art_apex_postinstall.te Sepolicy: Fix comment on apexd:fd use 2019-03-15 11:26:05 -07:00
art_apex_preinstall.te Sepolicy: Fix comment on apexd:fd use 2019-03-15 11:26:05 -07:00
asan_extract.te
atrace.te More neverallows for default_android_service. 2020-01-21 11:13:22 -08:00
audioserver.te Allow audio_server to access soundtrigger_middleware service 2019-12-12 10:56:35 -08:00
auditctl.te Add policy for /system/bin/auditctl 2019-04-09 20:55:30 -07:00
automotive_display_service.te Sepolicy update for Automotive Display Service 2020-01-21 18:43:27 +00:00
automotive_display_service_server.te Sepolicy update for Automotive Display Service 2020-01-21 18:43:27 +00:00
binder_in_vendor_violators.te
binderservicedomain.te
blank_screen.te Add rules for Lights AIDL HAL 2020-01-22 20:33:42 +01:00
blkid.te Introduce system_file_type 2018-09-27 12:52:09 -07:00
blkid_untrusted.te
bluetooth.te Support for more binder caches 2020-01-22 08:21:08 -08:00
bluetoothdomain.te
bootanim.te Dontaudit denials caused by race with labeling. 2018-02-14 17:07:13 -08:00
bootstat.te
boringssl_self_test.te SEPolicy changes to allow vendor BoringSSL self test. 2019-10-01 14:14:36 +01:00
bpfloader.te Allow system_server to attach bpf programs to tracepoints 2020-01-31 19:47:24 -08:00
bufferhubd.te Remove unused bufferhub sepolicy 2018-12-10 13:36:11 -08:00
bug_map Temporarily whitelist system_server->storage denials 2020-01-06 14:28:31 +01:00
cameraserver.te Abstract use of cameraserver behind an attribute 2019-03-01 14:02:59 -08:00
charger.te
clatd.te sepolicy - move public clatd to private 2019-05-11 17:47:25 -07:00
coredomain.te Allow system_server to attach bpf programs to tracepoints 2020-01-31 19:47:24 -08:00
cppreopts.te Sepolicy: Clean up moved files 2019-02-22 08:36:41 -08:00
crash_dump.te crash_dump: suppress devpts denials 2019-03-19 04:05:51 +00:00
derive_sdk.te Rename sdkext sepolicy to sdkextensions 2020-01-08 11:41:18 +00:00
dex2oat.te Allow otapreopt_chroot to use a flattened Runtime APEX package. 2019-03-19 14:44:22 +00:00
dexoptanalyzer.te Allow dexoptanalyzer to mmap files with Linux 4.14+ that it can already access. 2019-08-16 20:02:32 +01:00
dhcp.te
dnsmasq.te
domain.te Add sepolicy rules to allow apexd to perform snapshot and restore. 2020-01-27 18:21:29 +00:00
drmserver.te
dumpstate.te dumpstate: reads ota_metadata_file 2019-10-29 14:29:54 -07:00
ephemeral_app.te initial policy for traced_perf daemon (perf profiler) 2020-01-22 22:04:01 +00:00
fastbootd.te Add sepolicy for fastbootd 2018-08-15 08:45:22 -07:00
file.te Move linker config under /linkerconfig 2019-12-05 12:42:29 +09:00
file_contexts Merge "snapshotctl better logging" 2020-02-04 22:18:33 +00:00
file_contexts_asan fix data/asan/product/lib(64) can't access by platform_app issue 2019-07-19 03:23:47 +00:00
file_contexts_overlayfs fs_mgr: add /mnt/scratch to possible overlayfs support directories 2018-10-08 14:23:01 +00:00
fingerprintd.te
flags_health_check.te sepolicy for server configurable flags 2018-11-01 03:28:56 +00:00
fs_use fs_mgr: add overlayfs handling for squashfs system filesystems 2018-08-08 07:33:10 -07:00
fsck.te
fsck_untrusted.te
fsverity_init.te Merge "Revert "sepolicy: dontaudit cap_sys_admin on userdebug/eng"" 2019-11-21 22:27:37 +00:00
fwk_bufferhub.te Allow bufferhub service to allocate buffer 2018-11-07 13:57:55 -08:00
gatekeeperd.te
genfs_contexts Merge "Allow init to configure dm_verity kernel driver." 2020-01-15 13:13:01 +00:00
gmscore_app.te gmscore_app: Enforce all rules for the domain 2020-01-07 10:53:49 -08:00
gpuservice.te Allow dumpstate to dumpsys gpu 2019-05-09 23:15:49 -07:00
gsid.te Make the sepolicy for gsid cleaner 2020-01-17 14:23:53 +08:00
hal_allocator_default.te sepolicy: remove ashmemd 2019-09-27 17:43:53 +00:00
halclientdomain.te
halserverdomain.te
healthd.te
heapprofd.te Allow Java domains to be Perfetto producers. 2019-10-10 10:40:26 +01:00
hwservice_contexts Sepolicy update for Automotive Display Service 2020-01-21 18:43:27 +00:00
hwservicemanager.te Finer grained permissions for ctl. properties 2018-05-22 13:47:16 -07:00
idmap.te Add idmap2 and idmap2d 2018-11-15 14:42:10 +00:00
incident.te Allow dumpstate to call incident CLI 2019-08-21 16:10:39 -07:00
incident_helper.te Allow dumpstate to dump incidentd 2018-12-04 15:42:56 -08:00
incidentd.te Allow incidentd to parse persisted log 2020-01-18 16:18:18 -08:00
init.te Add sysprop for init's perf_event_open LSM hook check 2020-01-21 19:03:33 +00:00
initial_sid_contexts
initial_sids
inputflinger.te
installd.te sepolicy: allow rules for apk verify system property 2019-12-03 10:09:35 -08:00
iorap_prefecherd.te sepolicy: Add iorap_prefetcherd rules 2019-10-22 12:45:46 -07:00
iorapd.te Allow iorapd to access the runtime native boot feature flag properties 2019-12-04 20:56:54 +00:00
isolated_app.te initial policy for traced_perf daemon (perf profiler) 2020-01-22 22:04:01 +00:00
iw.te Allow iw to be run at init phase. 2018-11-14 19:10:12 +00:00
kernel.te Sepolicy: Move otapreopt_chroot to private 2019-03-18 10:54:42 -07:00
keys.conf Don't require seinfo for priv-apps 2019-11-06 08:37:03 -08:00
keystore.te sepolicy: Move wifi keystore HAL service to wificond 2019-10-28 14:06:17 -07:00
linkerconfig.te Update linkerconfig to generate APEX binary config 2020-01-20 13:40:08 +09:00
llkd.te llkd: requires sys_admin permissions 2020-01-15 08:08:59 -08:00
lmkd.te
logd.te Revert "sepolicy: Permission changes for new wifi mainline module" 2019-11-22 09:49:32 -08:00
logpersist.te Allow incidentd to parse persisted log 2020-01-18 16:18:18 -08:00
lpdumpd.te binder_use: Allow servicemanager callbacks 2019-12-19 23:07:14 +00:00
mac_permissions.xml Don't require seinfo for priv-apps 2019-11-06 08:37:03 -08:00
mdnsd.te Introduce system_file_type 2018-09-27 12:52:09 -07:00
mediadrmserver.te
mediaextractor.te Initial selinux policy support for memfd 2019-01-30 19:11:49 +00:00
mediametrics.te
mediaprovider.te Merge "Revert "Allow MediaProvider to host FUSE devices."" 2020-01-10 21:17:15 +00:00
mediaprovider_app.te Create new mediaprovider_app domain. 2020-02-04 16:53:18 +01:00
mediaserver.te allow mediaserver to use appdomain_tmpfs 2019-12-05 12:14:13 -08:00
mediaswcodec.te add mediaswcodec service 2018-10-11 15:10:17 -07:00
mediatranscoding.te MediaTranscodingService: Add sepolicy for MediaTranscodingService. 2019-12-02 13:57:28 -08:00
migrate_legacy_obb_data.te sepolicy: Adjust policy for migrate_legacy_obb_data.sh 2019-07-16 02:55:25 +00:00
mls Initial selinux policy support for memfd 2019-01-30 19:11:49 +00:00
mls_decl
mls_macros
modprobe.te
mtp.te
netd.te sepolicy - move public clatd to private 2019-05-11 17:47:25 -07:00
netutils_wrapper.te Sepolicy for netutils_wrapper to use binder call 2019-04-26 02:46:39 +00:00
network_stack.te Allow tethering find netork stack service 2019-12-12 12:54:57 +08:00
nfc.te Remove mediacodec_service. 2019-08-21 01:19:20 +00:00
notify_traceur.te Allow the init process to execute the notify_traceur.sh script 2019-02-07 00:28:40 +00:00
otapreopt_chroot.te Sepolicy: Allow otapreopt to mount logical partitions 2019-03-22 12:13:05 -07:00
otapreopt_slot.te Sepolicy: Clean up moved files 2019-02-22 08:36:41 -08:00
perfetto.te Allow Perfetto to log to statsd 2019-11-04 12:23:27 +00:00
performanced.te
permissioncontroller_app.te Don't run permissioncontroller_app in permissive mode 2020-01-06 09:41:22 -08:00
platform_app.te Revert "Make platform_compat discoverable everywhere" 2020-01-30 21:38:35 +00:00
policy_capabilities Add nnp_nosuid_transition policycap and related class/perm definitions. 2018-09-07 10:52:31 -07:00
port_contexts
postinstall.te
postinstall_dexopt.te Sepolicy: Allow otapreopt access to vendor overlay files 2019-03-22 12:13:53 -07:00
ppp.te
preloads_copy.te Add sepolicy for preloads_copy script 2018-10-23 17:11:36 +01:00
preopt2cachename.te Sepolicy: Clean up moved files 2019-02-22 08:36:41 -08:00
priv_app.te Create new mediaprovider_app domain. 2020-02-04 16:53:18 +01:00
profman.te
property_contexts Merge "Whitelisting window_manager_native_boot system property" 2020-01-24 19:52:07 +00:00
racoon.te
radio.te Allow telephony access to platform_compat 2019-12-06 13:18:21 -08:00
recovery.te
recovery_persist.te In native coverage builds, allow all domains to access /data/misc/trace 2019-06-19 16:27:17 -07:00
recovery_refresh.te In native coverage builds, allow all domains to access /data/misc/trace 2019-06-19 16:27:17 -07:00
roles_decl
rs.te rs.te: Allow ephemeral_app FD use 2019-04-02 13:59:39 -07:00
rss_hwm_reset.te SELinux policy for rss_hwm_reset 2018-12-15 10:13:03 +00:00
runas.te
runas_app.te perf_event: rules for system and simpleperf domain 2020-01-15 16:56:41 +00:00
sdcardd.te
seapp_contexts Create new mediaprovider_app domain. 2020-02-04 16:53:18 +01:00
secure_element.te SE Policy for Secure Element app and Secure Element HAL 2018-01-29 21:31:42 +00:00
security_classes perf_event: define security class and access vectors 2020-01-13 14:56:54 +00:00
service.te system_server: create StatsManagerService 2019-12-16 11:50:16 -08:00
service_contexts Add rules for Lights AIDL HAL 2020-01-22 20:33:42 +01:00
servicemanager.te Allow servicemanager to start processes 2019-08-02 00:23:16 +00:00
sgdisk.te
shared_relro.te
shell.te perf_event: rules for system and simpleperf domain 2020-01-15 16:56:41 +00:00
simpleperf.te perf_event: rules for system and simpleperf domain 2020-01-15 16:56:41 +00:00
simpleperf_app_runner.te Add sepolicy for simpleperf_app_runner. 2019-01-23 23:23:09 +00:00
slideshow.te
snapshotctl.te snapshotctl better logging 2020-02-04 10:09:24 -08:00
stats.te [SfStats] sepolicy for SfStats' global puller 2020-01-10 16:34:48 -08:00
statsd.te [SfStats] sepolicy for SfStats' global puller 2020-01-10 16:34:48 -08:00
storaged.te Allow GMS core to call dumpsys storaged 2019-12-11 12:49:04 -08:00
su.te SELinux policies for Perfetto cmdline client (/system/bin/perfetto) 2018-01-29 11:06:00 +00:00
surfaceflinger.te [SfStats] sepolicy for SfStats' global puller 2020-01-10 16:34:48 -08:00
system_app.te More neverallows for default_android_service. 2020-01-21 11:13:22 -08:00
system_server.te Allow system_server to attach bpf programs to tracepoints 2020-01-31 19:47:24 -08:00
system_server_startup.te system_server_startup: allow SIGCHLD to zygote 2019-06-14 16:56:05 -07:00
system_suspend.te system_suspend: sysfs path resolution 2019-11-12 13:47:26 -08:00
technical_debt.cil Allow apps to access hal_drm 2019-09-30 04:51:24 +00:00
tombstoned.te
toolbox.te
traced.te Root of /data belongs to init (re-landing) 2019-09-09 14:42:01 -07:00
traced_perf.te initial policy for traced_perf daemon (perf profiler) 2020-01-22 22:04:01 +00:00
traced_probes.te Allow Java domains to be Perfetto producers. 2019-10-10 10:40:26 +01:00
traceur_app.te Allow the Traceur app to start Perfetto. 2018-12-10 18:51:29 -08:00
tzdatacheck.te
ueventd.te
uncrypt.te
untrusted_app.te reland: untrusted_app_29: add new targetSdk domain 2020-01-22 09:47:53 +00:00
untrusted_app_25.te reland: untrusted_app_29: add new targetSdk domain 2020-01-22 09:47:53 +00:00
untrusted_app_27.te reland: untrusted_app_29: add new targetSdk domain 2020-01-22 09:47:53 +00:00
untrusted_app_29.te reland: untrusted_app_29: add new targetSdk domain 2020-01-22 09:47:53 +00:00
untrusted_app_all.te initial policy for traced_perf daemon (perf profiler) 2020-01-22 22:04:01 +00:00
update_engine.te update_engine: rules to apply virtual A/B OTA 2019-10-02 12:46:47 -07:00
update_engine_common.te
update_verifier.te
usbd.te
users
vdc.te
vendor_init.te Root of /data belongs to init (re-landing) 2019-09-09 14:42:01 -07:00
viewcompiler.te Give map permission to viewcompiler 2019-08-27 10:43:55 -07:00
virtual_touchpad.te
vold.te Abolish calls to shell in vold 2018-11-30 16:02:04 -08:00
vold_prepare_subdirs.te Add policies for permission APEX data directory. 2020-01-16 16:08:55 -08:00
vr_hwc.te
vzwomatrigger_app.te Don't run vzwomatrigger_app in permissive mode 2019-12-02 09:41:54 -08:00
wait_for_keymaster.te Introduce system_file_type 2018-09-27 12:52:09 -07:00
watchdogd.te Move watchdogd out of init and into its own domain 2018-08-03 19:28:05 +00:00
webview_zygote.te Add getattr access on tmpfs_zygote files for webview_zygote. 2020-01-30 21:29:19 +00:00
wificond.te
wpantund.te
zygote.te Merge "Grant vold, installd, zygote and apps access to /mnt/pass_through" 2020-01-28 22:26:58 +00:00