Skip to content
Snippets Groups Projects
Commit 099fed44 authored by TreeHugger Robot's avatar TreeHugger Robot Committed by Android (Google) Code Review
Browse files

Merge "Remove WiFi permissions from netd"

parents 9c9c5d09 fb5b13ee
No related branches found
No related tags found
No related merge requests found
...@@ -38,18 +38,13 @@ r_dir_file(netd, sysfs_type) ...@@ -38,18 +38,13 @@ r_dir_file(netd, sysfs_type)
# Allows setting interface MTU # Allows setting interface MTU
allow netd sysfs:file write; allow netd sysfs:file write;
# For /sys/modules/bcmdhd/parameters/firmware_path
allow netd sysfs_wlan_fwpath:file w_file_perms;
# TODO: added to match above sysfs rule. Remove me? # TODO: added to match above sysfs rule. Remove me?
allow netd sysfs_usb:file write; allow netd sysfs_usb:file write;
# Needed to update /data/misc/wifi/hostapd.conf # TODO: netd previously thought it needed these permissions to do WiFi related
# TODO: See what we can do to reduce the need for # work. However, after all the WiFi stuff is gone, we still need them.
# these capabilities # Why?
allow netd self:capability { dac_override chown fowner }; allow netd self:capability { dac_override chown };
allow netd wifi_data_file:file create_file_perms;
allow netd wifi_data_file:dir rw_dir_perms;
# Needed to update /data/misc/net/rt_tables # Needed to update /data/misc/net/rt_tables
allow netd net_data_file:file create_file_perms; allow netd net_data_file:file create_file_perms;
...@@ -81,9 +76,6 @@ allow netd dns_listener_service:service_manager find; ...@@ -81,9 +76,6 @@ allow netd dns_listener_service:service_manager find;
allow netd netdomain:{tcp_socket udp_socket rawip_socket dccp_socket tun_socket} {read write getattr setattr getopt setopt}; allow netd netdomain:{tcp_socket udp_socket rawip_socket dccp_socket tun_socket} {read write getattr setattr getopt setopt};
allow netd netdomain:fd use; allow netd netdomain:fd use;
# Allow netd to start and stop hostapd via ctl.start/stop
set_prop(netd, ctl_default_prop)
### ###
### Neverallow rules ### Neverallow rules
### ###
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment