344fc109e9
Add SELinux MAC for the service manager actions list
and find. Add the list and find verbs to the
service_manager class. Add policy requirements for
service_manager to enforce policies to binder_use
macro.
(cherry picked from commit b8511e0d98
)
Change-Id: I980d4a8acf6a0c6e99a3a7905961eb5564b1be15
25 lines
592 B
Text
25 lines
592 B
Text
# nfc subsystem
|
|
type nfc, domain;
|
|
app_domain(nfc)
|
|
net_domain(nfc)
|
|
binder_service(nfc)
|
|
|
|
# NFC device access.
|
|
allow nfc nfc_device:chr_file rw_file_perms;
|
|
|
|
# Data file accesses.
|
|
allow nfc nfc_data_file:dir create_dir_perms;
|
|
allow nfc nfc_data_file:notdevfile_class_set create_file_perms;
|
|
|
|
allow nfc sysfs_nfc_power_writable:file rw_file_perms;
|
|
allow nfc sysfs:file write;
|
|
|
|
allow nfc nfc_service:service_manager add;
|
|
|
|
# Audited locally.
|
|
service_manager_local_audit_domain(nfc)
|
|
auditallow nfc {
|
|
service_manager_type
|
|
-mediaserver_service
|
|
-system_server_service
|
|
}:service_manager find;
|