8224596a32
Renaming the wifi HIDL implementation to 'hal_wifi' from 'wifi_hal_legacy' to conform with HIDL style guide. Denials: 01-01 21:55:23.896 2865 2865 I android.hardware.wifi@1.0-service: wifi_hal_legacy is starting up... 01-01 21:55:23.898 2865 2865 W android.hardware.wifi@1.0-service: /odm/lib64/hw/ does not exit. 01-01 21:55:23.899 2865 2865 F android.hardware.wifi@1.0-service: service.cpp:59] Check failed: service->registerAsService("wifi") == android::NO_ERROR (service->registerAsService("wifi")=-2147483646, android::NO_ERROR=0) Failed to register wifi HAL 01-01 21:55:23.899 2865 2865 F libc : Fatal signal 6 (SIGABRT), code -6 in tid 2865 (android.hardwar) 01-01 21:55:23.901 377 377 W : debuggerd: handling request: pid=2865 uid=2000 gid=2000 tid=2865 01-01 21:55:23.907 2867 2867 E : debuggerd: Unable to connect to activity manager (connect failed: Connection refused) 01-01 21:55:23.908 2867 2867 F DEBUG : *** *** *** *** *** *** *** *** *** *** *** *** *** *** *** *** 01-01 21:55:23.908 2867 2867 F DEBUG : Build fingerprint: 'Android/aosp_angler/angler:7.0/NYC/rpius10031052:userdebug/test-keys' 01-01 21:55:23.908 2867 2867 F DEBUG : Revision: '0' 01-01 21:55:23.908 2867 2867 F DEBUG : ABI: 'arm64' 01-01 21:55:23.908 2867 2867 F DEBUG : pid: 2865, tid: 2865, name: android.hardwar >>> /system/bin/hw/android.hardware.wifi@1.0-service <<< 01-01 21:55:23.909 2867 2867 F DEBUG : signal 6 (SIGABRT), code -6 (SI_TKILL), fault addr -------- 01-01 21:55:23.910 2867 2867 F DEBUG : Abort message: 'service.cpp:59] Check failed: service->registerAsService("wifi") == android::NO_ERROR (service->registerAsService("wifi")=-2147483646, android::NO_ERROR=0) Failed to register wifi HAL' Bug: 31821133 Test: Compiled and ensured that the selinux denials are no longer present in logs. Change-Id: I5bbbcad307e9bb9e59fff87e2926751b3aecc813
49 lines
1.8 KiB
Text
49 lines
1.8 KiB
Text
# wificond
|
|
type wificond, domain;
|
|
type wificond_exec, exec_type, file_type;
|
|
|
|
binder_use(wificond)
|
|
binder_call(wificond, system_server)
|
|
|
|
hwbinder_use(wificond)
|
|
binder_call(wificond, hal_wifi)
|
|
binder_call(wificond, wpa)
|
|
|
|
allow wificond wificond_service:service_manager { add find };
|
|
|
|
# wificond writes firmware paths to this file.
|
|
# wificond also changes the owership of this file on startup.
|
|
allow wificond sysfs_wlan_fwpath:file { w_file_perms setattr };
|
|
|
|
set_prop(wificond, wifi_prop)
|
|
set_prop(wificond, ctl_default_prop)
|
|
|
|
# create sockets to set interfaces up and down
|
|
allow wificond self:udp_socket create_socket_perms;
|
|
# setting interface state up/down is a privileged ioctl
|
|
allowxperm wificond self:udp_socket ioctl { SIOCSIFFLAGS };
|
|
allow wificond self:capability { net_admin net_raw };
|
|
# allow wificond to speak to nl80211 in the kernel
|
|
allow wificond self:netlink_socket create_socket_perms_no_ioctl;
|
|
# newer kernels (e.g. 4.4 but not 4.1) have a new class for sockets
|
|
allow wificond self:netlink_generic_socket create_socket_perms_no_ioctl;
|
|
|
|
r_dir_file(wificond, proc_net)
|
|
|
|
# wificond writes out configuration files for wpa_supplicant/hostapd.
|
|
# wificond also reads pid files out of this directory
|
|
allow wificond wifi_data_file:dir rw_dir_perms;
|
|
allow wificond wifi_data_file:file create_file_perms;
|
|
|
|
# wificond drops root shortly after starting
|
|
# wificond changes the ownership of some files before dropping root
|
|
allow wificond self:capability { setuid setgid setpcap chown };
|
|
|
|
# wificond cleans up sockets created by wpa_supplicant and framework
|
|
allow wificond wpa_socket:dir rw_dir_perms;
|
|
allow wificond system_wpa_socket:sock_file unlink;
|
|
allow wificond wpa_socket:sock_file unlink;
|
|
|
|
# dumpstate support
|
|
allow wificond dumpstate:fd use;
|
|
allow wificond dumpstate:fifo_file write;
|