Skip to content
Snippets Groups Projects
  • Jeff Vander Stoep's avatar
    nfc: allow access to drmserver_service · 24ad5862
    Jeff Vander Stoep authored
    avc:  denied  { find } for service=drm.drmManager pid=4320 uid=1027 scontext=u:r:nfc:s0 tcontext=u:object_r:drmserver_service:s0 tclass=service_manager
    
    Arrange in alphabetical order.
    
    Bug: 30112127
    Change-Id: I6592497a937c6a6d2c7c3d444beba3db333f4852
    24ad5862
nfc.te 1.23 KiB
# nfc subsystem
type nfc, domain, domain_deprecated;
app_domain(nfc)
net_domain(nfc)
binder_service(nfc)

# Set NFC properties
set_prop(nfc, nfc_prop)

# NFC device access.
allow nfc nfc_device:chr_file rw_file_perms;

# Data file accesses.
allow nfc nfc_data_file:dir create_dir_perms;
allow nfc nfc_data_file:notdevfile_class_set create_file_perms;

allow nfc sysfs_nfc_power_writable:file rw_file_perms;
allow nfc sysfs:file write;

# TODO: added to match above sysfs rule. Remove me?
allow nfc sysfs_usb:file write;

# SoundPool loading and playback
allow nfc audioserver_service:service_manager find;
allow nfc drmserver_service:service_manager find;
allow nfc mediacodec_service:service_manager find;
allow nfc mediaextractor_service:service_manager find;
allow nfc mediaserver_service:service_manager find;

allow nfc nfc_service:service_manager { add find };
allow nfc radio_service:service_manager find;
allow nfc surfaceflinger_service:service_manager find;
allow nfc app_api_service:service_manager find;
allow nfc system_api_service:service_manager find;

# already open bugreport file descriptors may be shared with
# the nfc process, from a file in
# /data/data/com.android.shell/files/bugreports/bugreport-*.
allow nfc shell_data_file:file read;