Skip to content
Snippets Groups Projects
  • Riley Spahn's avatar
    Add access control for each service_manager action. · 344fc109
    Riley Spahn authored
    Add SELinux MAC for the service manager actions list
    and find. Add the list and find verbs to the
    service_manager class. Add policy requirements for
    service_manager to enforce policies to binder_use
    macro.
    
    (cherry picked from commit b8511e0d)
    
    Change-Id: I980d4a8acf6a0c6e99a3a7905961eb5564b1be15
    344fc109
servicemanager.te 632 B
# servicemanager - the Binder context manager
type servicemanager, domain;
type servicemanager_exec, exec_type, file_type;

init_daemon_domain(servicemanager)

# Note that we do not use the binder_* macros here.
# servicemanager is unique in that it only provides
# name service (aka context manager) for Binder.
# As such, it only ever receives and transfers other references
# created by other domains.  It never passes its own references
# or initiates a Binder IPC.
allow servicemanager self:binder set_context_mgr;
allow servicemanager domain:binder transfer;

# Check SELinux permissions.
selinux_check_access(servicemanager)