Skip to content
Snippets Groups Projects
Commit 2f3ccbbe authored by Chalard Jean's avatar Chalard Jean Committed by android-build-merger
Browse files

Add sepolicy for IpMemoryStoreService am: fb15c9f1

am: bb05d23d

Change-Id: Iebc05979693943db196df9dc961dfe61515b5921
parents 3835978a bb05d23d
No related branches found
No related tags found
No related merge requests found
...@@ -23,3 +23,6 @@ neverallow { appdomain -shell userdebug_or_eng(`-su') } ...@@ -23,3 +23,6 @@ neverallow { appdomain -shell userdebug_or_eng(`-su') }
{ domain -appdomain -crash_dump -rs }:process { transition }; { domain -appdomain -crash_dump -rs }:process { transition };
neverallow { appdomain -shell userdebug_or_eng(`-su') } neverallow { appdomain -shell userdebug_or_eng(`-su') }
{ domain -appdomain }:process { dyntransition }; { domain -appdomain }:process { dyntransition };
# Disallow apps from using IP memory store
neverallow { appdomain -shell } ipmemorystore_service:service_manager *;
...@@ -102,6 +102,7 @@ ...@@ -102,6 +102,7 @@
iorapd_exec iorapd_exec
iorapd_service iorapd_service
iorapd_tmpfs iorapd_tmpfs
ipmemorystore_service
kmsg_debug_device kmsg_debug_device
last_boot_reason_prop last_boot_reason_prop
llkd llkd
......
...@@ -93,6 +93,7 @@ ...@@ -93,6 +93,7 @@
iorapd_exec iorapd_exec
iorapd_service iorapd_service
iorapd_tmpfs iorapd_tmpfs
ipmemorystore_service
last_boot_reason_prop last_boot_reason_prop
llkd llkd
llkd_exec llkd_exec
......
...@@ -47,6 +47,7 @@ ...@@ -47,6 +47,7 @@
heapprofd_prop heapprofd_prop
heapprofd_socket heapprofd_socket
idmap_service idmap_service
ipmemorystore_service
iris_service iris_service
iris_vendor_data_file iris_vendor_data_file
llkd llkd
......
...@@ -82,6 +82,7 @@ iphonesubinfo2 u:object_r:radio_service:s0 ...@@ -82,6 +82,7 @@ iphonesubinfo2 u:object_r:radio_service:s0
iphonesubinfo u:object_r:radio_service:s0 iphonesubinfo u:object_r:radio_service:s0
ims u:object_r:radio_service:s0 ims u:object_r:radio_service:s0
imms u:object_r:imms_service:s0 imms u:object_r:imms_service:s0
ipmemorystore u:object_r:ipmemorystore_service:s0
ipsec u:object_r:ipsec_service:s0 ipsec u:object_r:ipsec_service:s0
iris u:object_r:iris_service:s0 iris u:object_r:iris_service:s0
isms_msim u:object_r:radio_service:s0 isms_msim u:object_r:radio_service:s0
......
...@@ -74,6 +74,7 @@ allow system_app { ...@@ -74,6 +74,7 @@ allow system_app {
-dumpstate_service -dumpstate_service
-installd_service -installd_service
-iorapd_service -iorapd_service
-ipmemorystore_service
-netd_service -netd_service
-virtual_touchpad_service -virtual_touchpad_service
-vold_service -vold_service
......
...@@ -101,6 +101,7 @@ type hdmi_control_service, system_api_service, system_server_service, service_ma ...@@ -101,6 +101,7 @@ type hdmi_control_service, system_api_service, system_server_service, service_ma
type imms_service, app_api_service, ephemeral_app_api_service, system_server_service, service_manager_type; type imms_service, app_api_service, ephemeral_app_api_service, system_server_service, service_manager_type;
type input_method_service, app_api_service, ephemeral_app_api_service, system_server_service, service_manager_type; type input_method_service, app_api_service, ephemeral_app_api_service, system_server_service, service_manager_type;
type input_service, app_api_service, ephemeral_app_api_service, system_server_service, service_manager_type; type input_service, app_api_service, ephemeral_app_api_service, system_server_service, service_manager_type;
type ipmemorystore_service, system_server_service, service_manager_type;
type ipsec_service, app_api_service, ephemeral_app_api_service, system_server_service, service_manager_type; type ipsec_service, app_api_service, ephemeral_app_api_service, system_server_service, service_manager_type;
type iris_service, app_api_service, system_server_service, service_manager_type; type iris_service, app_api_service, system_server_service, service_manager_type;
type jobscheduler_service, app_api_service, ephemeral_app_api_service, system_server_service, service_manager_type; type jobscheduler_service, app_api_service, ephemeral_app_api_service, system_server_service, service_manager_type;
......
...@@ -11,6 +11,7 @@ allow traceur_app { ...@@ -11,6 +11,7 @@ allow traceur_app {
-gatekeeper_service -gatekeeper_service
-incident_service -incident_service
-installd_service -installd_service
-ipmemorystore_service
-iorapd_service -iorapd_service
-netd_service -netd_service
-virtual_touchpad_service -virtual_touchpad_service
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment