Skip to content
Snippets Groups Projects
Commit 4cdea7fc authored by dcashman's avatar dcashman
Browse files

Assign app_api_service attribute to services.

Assign the alarm, appwidget, assetatlas, audio, backup and batterystats services
the appropriate service access levels and move into enforcing.

Bug: 18106000
Change-Id: If3210bb25f3076edfdb6eec36ef6521ace1bd8d7
parent b075338d
No related branches found
No related tags found
No related merge requests found
...@@ -60,7 +60,6 @@ allow bluetooth system_api_service:service_manager find; ...@@ -60,7 +60,6 @@ allow bluetooth system_api_service:service_manager find;
service_manager_local_audit_domain(bluetooth) service_manager_local_audit_domain(bluetooth)
auditallow bluetooth { auditallow bluetooth {
tmp_system_server_service tmp_system_server_service
-audio_service
-bluetooth_manager_service -bluetooth_manager_service
-connectivity_service -connectivity_service
-display_service -display_service
......
...@@ -80,6 +80,7 @@ allow mediaserver tee:unix_stream_socket connectto; ...@@ -80,6 +80,7 @@ allow mediaserver tee:unix_stream_socket connectto;
allow mediaserver activity_service:service_manager find; allow mediaserver activity_service:service_manager find;
allow mediaserver appops_service:service_manager find; allow mediaserver appops_service:service_manager find;
allow mediaserver batterystats_service:service_manager find;
allow mediaserver drmserver_service:service_manager find; allow mediaserver drmserver_service:service_manager find;
allow mediaserver mediaserver_service:service_manager { add find }; allow mediaserver mediaserver_service:service_manager { add find };
allow mediaserver surfaceflinger_service:service_manager find; allow mediaserver surfaceflinger_service:service_manager find;
...@@ -88,7 +89,6 @@ allow mediaserver tmp_system_server_service:service_manager find; ...@@ -88,7 +89,6 @@ allow mediaserver tmp_system_server_service:service_manager find;
service_manager_local_audit_domain(mediaserver) service_manager_local_audit_domain(mediaserver)
auditallow mediaserver { auditallow mediaserver {
tmp_system_server_service tmp_system_server_service
-batterystats_service
-permission_service -permission_service
-power_service -power_service
-processinfo_service -processinfo_service
......
...@@ -30,7 +30,6 @@ allow nfc system_api_service:service_manager find; ...@@ -30,7 +30,6 @@ allow nfc system_api_service:service_manager find;
service_manager_local_audit_domain(nfc) service_manager_local_audit_domain(nfc)
auditallow nfc { auditallow nfc {
tmp_system_server_service tmp_system_server_service
-batterystats_service
-bluetooth_manager_service -bluetooth_manager_service
-connectivity_service -connectivity_service
-content_service -content_service
......
...@@ -39,10 +39,6 @@ allow platform_app system_api_service:service_manager find; ...@@ -39,10 +39,6 @@ allow platform_app system_api_service:service_manager find;
service_manager_local_audit_domain(platform_app) service_manager_local_audit_domain(platform_app)
auditallow platform_app { auditallow platform_app {
tmp_system_server_service tmp_system_server_service
-appwidget_service
-assetatlas_service
-audio_service
-batterystats_service
-bluetooth_manager_service -bluetooth_manager_service
-connectivity_service -connectivity_service
-content_service -content_service
......
...@@ -41,7 +41,6 @@ allow radio system_api_service:service_manager find; ...@@ -41,7 +41,6 @@ allow radio system_api_service:service_manager find;
service_manager_local_audit_domain(radio) service_manager_local_audit_domain(radio)
auditallow radio { auditallow radio {
tmp_system_server_service tmp_system_server_service
-assetatlas_service
-bluetooth_manager_service -bluetooth_manager_service
-connectivity_service -connectivity_service
-content_service -content_service
......
...@@ -14,13 +14,13 @@ type system_app_service, service_manager_type; ...@@ -14,13 +14,13 @@ type system_app_service, service_manager_type;
type accessibility_service, app_api_service, system_server_service, service_manager_type; type accessibility_service, app_api_service, system_server_service, service_manager_type;
type account_service, app_api_service, system_server_service, service_manager_type; type account_service, app_api_service, system_server_service, service_manager_type;
type activity_service, app_api_service, system_server_service, service_manager_type; type activity_service, app_api_service, system_server_service, service_manager_type;
type alarm_service, tmp_system_server_service, service_manager_type; type alarm_service, app_api_service, system_server_service, service_manager_type;
type appops_service, app_api_service, system_server_service, service_manager_type; type appops_service, app_api_service, system_server_service, service_manager_type;
type appwidget_service, tmp_system_server_service, service_manager_type; type appwidget_service, app_api_service, system_server_service, service_manager_type;
type assetatlas_service, tmp_system_server_service, service_manager_type; type assetatlas_service, app_api_service, system_server_service, service_manager_type;
type audio_service, tmp_system_server_service, service_manager_type; type audio_service, app_api_service, system_server_service, service_manager_type;
type backup_service, tmp_system_server_service, service_manager_type; type backup_service, system_api_service, system_server_service, service_manager_type;
type batterystats_service, tmp_system_server_service, service_manager_type; type batterystats_service, app_api_service, system_server_service, service_manager_type;
type battery_service, tmp_system_server_service, service_manager_type; type battery_service, tmp_system_server_service, service_manager_type;
type bluetooth_manager_service, tmp_system_server_service, service_manager_type; type bluetooth_manager_service, tmp_system_server_service, service_manager_type;
type clipboard_service, tmp_system_server_service, service_manager_type; type clipboard_service, tmp_system_server_service, service_manager_type;
......
...@@ -60,10 +60,6 @@ allow system_app system_api_service:service_manager find; ...@@ -60,10 +60,6 @@ allow system_app system_api_service:service_manager find;
service_manager_local_audit_domain(system_app) service_manager_local_audit_domain(system_app)
auditallow system_app { auditallow system_app {
tmp_system_server_service tmp_system_server_service
-appwidget_service
-assetatlas_service
-audio_service
-backup_service
-bluetooth_manager_service -bluetooth_manager_service
-connectivity_service -connectivity_service
-content_service -content_service
......
...@@ -370,11 +370,6 @@ allow system_server tmp_system_server_service:service_manager { add find }; ...@@ -370,11 +370,6 @@ allow system_server tmp_system_server_service:service_manager { add find };
service_manager_local_audit_domain(system_server) service_manager_local_audit_domain(system_server)
auditallow system_server { auditallow system_server {
tmp_system_server_service tmp_system_server_service
-alarm_service
-assetatlas_service
-audio_service
-backup_service
-batterystats_service
-bluetooth_manager_service -bluetooth_manager_service
-connectivity_service -connectivity_service
-content_service -content_service
......
...@@ -90,12 +90,6 @@ allow untrusted_app system_api_service:service_manager find; ...@@ -90,12 +90,6 @@ allow untrusted_app system_api_service:service_manager find;
service_manager_local_audit_domain(untrusted_app) service_manager_local_audit_domain(untrusted_app)
auditallow untrusted_app { auditallow untrusted_app {
tmp_system_server_service tmp_system_server_service
-appwidget_service
-assetatlas_service
-audio_service
-backup_service
-battery_service
-batterystats_service
-bluetooth_manager_service -bluetooth_manager_service
-clipboard_service -clipboard_service
-connectivity_service -connectivity_service
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment