platform_system_sepolicy/private
Joel Galenson 312c3800b8 Simplify genfs labeling of tracefs.
The code used to look like this, but in commit
4cae28d43c we replaced the generic
regexes to improve performance.  Now that we've switched to genfs,
this no longer affects performance, so let's simplify the labeling.

Bug: 62413700
Test: Built, flashed, and booted two devices.  Verified that all of
the files have the correct context and that wifi, camera, and traceur
work.

Change-Id: I1a859d17075fa25543ee090cc7a7478391bc45c1
2017-07-05 12:39:27 -07:00
..
access_vectors Define smc_socket security class. 2017-06-26 22:02:28 +00:00
adbd.te Allow adbd and shell to read /proc/config.gz 2017-05-08 14:40:25 -07:00
app.te system_server is a client of configstore 2017-06-23 11:20:20 -07:00
app_neverallows.te Revert "Remove neverallow preventing hwservice access for apps." 2017-06-21 16:55:49 -07:00
asan_extract.te Sepolicy: Add ASAN-Extract 2017-04-05 13:09:29 -07:00
atrace.te Properly give some files the debugfs_tracing context only in debug mode. 2017-06-14 15:50:21 -07:00
attributes Move domain_deprecated into private policy 2017-05-15 13:37:59 -07:00
audioserver.te Allow audioserver to talk to bluetooth server 2017-04-28 20:02:48 +00:00
binder_in_vendor_violators.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
binderservicedomain.te Move binderservicedomain policy to private 2017-02-08 09:09:39 -08:00
blkid.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
blkid_untrusted.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
bluetooth.te Allow Bluetooth sys_nice and system_server setsched for Bluetooth HAL 2017-04-26 11:48:00 -07:00
bluetoothdomain.te Move bluetoothdomain policy to private 2017-02-06 15:32:08 -08:00
bootanim.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
bootstat.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
bufferhubd.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
cameraserver.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
charger.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
clatd.te Move domain_deprecated into private policy 2017-05-15 13:37:59 -07:00
cppreopts.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
crash_dump.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
dex2oat.te Move domain_deprecated into private policy 2017-05-15 13:37:59 -07:00
dexoptanalyzer.te dexoptanalyzer: suppress access(2) denial 2017-06-30 15:30:06 -07:00
dhcp.te Move domain_deprecated into private policy 2017-05-15 13:37:59 -07:00
dnsmasq.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
domain.te Add keystore_key:attest_unique_id to priv_app. 2017-04-12 06:39:14 -06:00
domain_deprecated.te domain_deprecated: remove ion access am: 88e4be54a6 am: 8745ac4363 am: c8338f2669 2017-07-03 02:55:01 +00:00
drmserver.te Tighten restrictions on core <-> vendor socket comms 2017-03-31 09:17:54 -07:00
dumpstate.te Move domain_deprecated into private policy 2017-05-15 13:37:59 -07:00
e2fs.te allow init to run mke2fs tools to format partitions 2017-05-09 10:58:45 -07:00
ephemeral_app.te cas: add CAS hal and switch to use hwservice 2017-06-16 13:28:36 -07:00
file.te Label /proc/config.gz 2017-02-16 12:07:01 -08:00
file_contexts Move file labeling to genfs_contexts. 2017-07-05 19:28:11 +00:00
file_contexts_asan Sepolicy: Fix asanwrapper 2017-04-19 16:33:45 -07:00
fingerprintd.te Move domain_deprecated into private policy 2017-05-15 13:37:59 -07:00
fs_use Split general policy into public and private components. 2016-10-06 13:09:06 -07:00
fsck.te Move domain_deprecated into private policy 2017-05-15 13:37:59 -07:00
fsck_untrusted.te Move domain_deprecated into private policy 2017-05-15 13:37:59 -07:00
gatekeeperd.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
genfs_contexts Simplify genfs labeling of tracefs. 2017-07-05 12:39:27 -07:00
hal_allocator_default.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
halclientdomain.te Restrict access to hwservicemanager 2017-04-21 09:54:53 -07:00
halserverdomain.te Allow hals to read hwservicemanager prop. 2017-03-23 01:50:50 +00:00
healthd.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
hwservice_contexts cas: add CAS hal and switch to use hwservice 2017-06-16 13:28:36 -07:00
hwservicemanager.te Restrict access to hwservicemanager 2017-04-21 09:54:53 -07:00
idmap.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
incident.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
incidentd.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
init.te Fix coredomain violation for modprobe 2017-06-05 08:09:18 -07:00
initial_sid_contexts Split general policy into public and private components. 2016-10-06 13:09:06 -07:00
initial_sids Split general policy into public and private components. 2016-10-06 13:09:06 -07:00
inputflinger.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
install_recovery.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
installd.te Move domain_deprecated into private policy 2017-05-15 13:37:59 -07:00
isolated_app.te Tighten isolated_app -> *Binder policy 2017-04-21 18:09:01 -07:00
kernel.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
keys.conf Split general policy into public and private components. 2016-10-06 13:09:06 -07:00
keystore.te Move domain_deprecated into private policy 2017-05-15 13:37:59 -07:00
lmkd.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
logd.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
logpersist.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
mac_permissions.xml Move MediaProvider to its own domain, add new MtpServer permissions 2016-12-12 11:05:33 -08:00
mdnsd.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
mediadrmserver.te update sepolicy for gralloc HAL 2017-03-30 14:43:35 -07:00
mediaextractor.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
mediametrics.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
mediaserver.te Restrict access to hwservicemanager 2017-04-21 09:54:53 -07:00
mls sepolicy: add version_policy tool and version non-platform policy. 2016-12-06 08:56:02 -08:00
mls_decl sepolicy: add version_policy tool and version non-platform policy. 2016-12-06 08:56:02 -08:00
mls_macros Split general policy into public and private components. 2016-10-06 13:09:06 -07:00
modprobe.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
mtp.te Move domain_deprecated into private policy 2017-05-15 13:37:59 -07:00
net.te Move netdomain policy to private 2017-02-06 15:02:00 -08:00
netd.te Move domain_deprecated into private policy 2017-05-15 13:37:59 -07:00
netutils_wrapper.te add netutils_wrappers 2017-04-14 22:57:27 -07:00
nfc.te Allows nfc to access vr_manager_service 2017-05-25 15:59:52 -07:00
otapreopt_chroot.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
otapreopt_slot.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
performanced.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
perfprofd.te Move domain_deprecated into private policy 2017-05-15 13:37:59 -07:00
platform_app.te Merge "cas: add CAS hal and switch to use hwservice" 2017-06-28 20:37:18 +00:00
policy_capabilities Define extended_socket_class policy capability and socket classes 2017-02-06 13:53:11 -05:00
port_contexts Split general policy into public and private components. 2016-10-06 13:09:06 -07:00
postinstall.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
postinstall_dexopt.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
ppp.te Move domain_deprecated into private policy 2017-05-15 13:37:59 -07:00
preopt2cachename.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
priv_app.te Merge "cas: add CAS hal and switch to use hwservice" 2017-06-28 20:37:18 +00:00
profman.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
property_contexts Sepolicy: Give asan_extract access to powerctl 2017-06-27 15:38:29 -07:00
racoon.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
radio.te Move domain_deprecated into private policy 2017-05-15 13:37:59 -07:00
recovery.te Move domain_deprecated into private policy 2017-05-15 13:37:59 -07:00
recovery_persist.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
recovery_refresh.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
roles_decl sepolicy: add version_policy tool and version non-platform policy. 2016-12-06 08:56:02 -08:00
runas.te Move domain_deprecated into private policy 2017-05-15 13:37:59 -07:00
sdcardd.te Move domain_deprecated into private policy 2017-05-15 13:37:59 -07:00
seapp_contexts Revert "Split mediaprovider from priv_app." 2017-06-07 18:20:20 -07:00
security_classes Define smc_socket security class. 2017-06-26 22:02:28 +00:00
service_contexts Merge "cas: add CAS hal and switch to use hwservice" 2017-06-28 20:37:18 +00:00
servicemanager.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
sgdisk.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
shared_relro.te Move domain_deprecated into private policy 2017-05-15 13:37:59 -07:00
shell.te Properly give some files the debugfs_tracing context only in debug mode. 2017-06-14 15:50:21 -07:00
slideshow.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
storaged.te Merge "storaged: add permissions for dumpstate" am: 611202ef53 am: 702605c62f 2017-05-09 15:37:27 +00:00
su.te su and perfprofd are coredomain too 2017-03-24 09:31:50 -07:00
surfaceflinger.te system_server is a client of configstore 2017-06-23 11:20:20 -07:00
system_app.te relax fuse_device neverallow rules 2017-04-26 11:43:40 -07:00
system_server.te Merge "Allow only system_server to read uid_time_in_state" am: 439364d20e am: e96aad0998 2017-07-01 13:04:04 +00:00
technical_debt.cil cas: add CAS hal and switch to use hwservice 2017-06-16 13:28:36 -07:00
tombstoned.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
toolbox.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
tzdatacheck.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
ueventd.te Move domain_deprecated into private policy 2017-05-15 13:37:59 -07:00
uncrypt.te Move domain_deprecated into private policy 2017-05-15 13:37:59 -07:00
untrusted_app.te Allow UDP Sockets to be returned from IpSecService 2017-04-12 11:32:18 -07:00
untrusted_app_25.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
untrusted_app_all.te cas: add CAS hal and switch to use hwservice 2017-06-16 13:28:36 -07:00
untrusted_v2_app.te cas: add CAS hal and switch to use hwservice 2017-06-16 13:28:36 -07:00
update_engine.te Move domain_deprecated into private policy 2017-05-15 13:37:59 -07:00
update_engine_common.te Split general policy into public and private components. 2016-10-06 13:09:06 -07:00
update_verifier.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
users Split general policy into public and private components. 2016-10-06 13:09:06 -07:00
vdc.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
virtual_touchpad.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
vold.te Move domain_deprecated into private policy 2017-05-15 13:37:59 -07:00
vr_hwc.te Restrict access to hwservicemanager 2017-04-21 09:54:53 -07:00
watchdogd.te Vendor domains must not use Binder 2017-03-24 07:54:00 -07:00
webview_zygote.te Define smc_socket security class. 2017-06-26 22:02:28 +00:00
wificond.te SE Policy for Wifi Offload HAL 2017-05-18 09:49:55 -07:00
zygote.te Allow zygote to access dir/file under /vendor/overlay 2017-04-08 17:36:22 +09:00