Skip to content
Snippets Groups Projects
Commit 5da72005 authored by Tri Vo's avatar Tri Vo
Browse files

Separate product_property_contexts out of system sepolicy.

Bug: 119305624
Test: normal/recovery boot aosp_taimen
Change-Id: Ib7a29a9f8f23dd917cc25c23c7612f9e4ae36ea0
parent ade74163
No related branches found
No related tags found
No related merge requests found
...@@ -287,6 +287,7 @@ LOCAL_REQUIRED_MODULES += \ ...@@ -287,6 +287,7 @@ LOCAL_REQUIRED_MODULES += \
product_sepolicy.cil \ product_sepolicy.cil \
product_file_contexts \ product_file_contexts \
product_hwservice_contexts \ product_hwservice_contexts \
product_property_contexts \
endif endif
include $(BUILD_PHONY_PACKAGE) include $(BUILD_PHONY_PACKAGE)
...@@ -1288,8 +1289,7 @@ endif ...@@ -1288,8 +1289,7 @@ endif
include $(BUILD_SYSTEM)/base_rules.mk include $(BUILD_SYSTEM)/base_rules.mk
# TODO(b/119305624): Move product-specific sepolicy out of plat_property_contexts. plat_pcfiles := $(call build_policy, property_contexts, $(PLAT_PRIVATE_POLICY))
plat_pcfiles := $(call build_policy, property_contexts, $(PLAT_PRIVATE_POLICY) $(PRODUCT_PRIVATE_POLICY))
ifeq ($(PRODUCT_COMPATIBLE_PROPERTY),true) ifeq ($(PRODUCT_COMPATIBLE_PROPERTY),true)
plat_pcfiles += $(LOCAL_PATH)/public/property_contexts plat_pcfiles += $(LOCAL_PATH)/public/property_contexts
endif endif
...@@ -1310,6 +1310,34 @@ built_plat_pc := $(LOCAL_BUILT_MODULE) ...@@ -1310,6 +1310,34 @@ built_plat_pc := $(LOCAL_BUILT_MODULE)
plat_pcfiles := plat_pcfiles :=
plat_property_contexts.tmp := plat_property_contexts.tmp :=
##################################
include $(CLEAR_VARS)
LOCAL_MODULE := product_property_contexts
LOCAL_MODULE_CLASS := ETC
LOCAL_MODULE_TAGS := optional
LOCAL_MODULE_PATH := $(TARGET_OUT_PRODUCT)/etc/selinux
include $(BUILD_SYSTEM)/base_rules.mk
product_pcfiles := $(call build_policy, property_contexts, $(PRODUCT_PRIVATE_POLICY))
product_property_contexts.tmp := $(intermediates)/product_property_contexts.tmp
$(product_property_contexts.tmp): PRIVATE_PC_FILES := $(product_pcfiles)
$(product_property_contexts.tmp): PRIVATE_ADDITIONAL_M4DEFS := $(LOCAL_ADDITIONAL_M4DEFS)
$(product_property_contexts.tmp): $(product_pcfiles)
@mkdir -p $(dir $@)
$(hide) m4 --fatal-warnings -s $(PRIVATE_ADDITIONAL_M4DEFS) $(PRIVATE_PC_FILES) > $@
$(LOCAL_BUILT_MODULE): PRIVATE_SEPOLICY := $(built_sepolicy)
$(LOCAL_BUILT_MODULE): $(product_property_contexts.tmp) $(built_sepolicy) $(HOST_OUT_EXECUTABLES)/property_info_checker
@mkdir -p $(dir $@)
$(hide) cp -f $< $@
$(hide) $(HOST_OUT_EXECUTABLES)/property_info_checker $(PRIVATE_SEPOLICY) $@
built_product_pc := $(LOCAL_BUILT_MODULE)
product_pcfiles :=
product_property_contexts.tmp :=
################################## ##################################
include $(CLEAR_VARS) include $(CLEAR_VARS)
LOCAL_MODULE := vendor_property_contexts LOCAL_MODULE := vendor_property_contexts
...@@ -1389,6 +1417,19 @@ include $(BUILD_SYSTEM)/base_rules.mk ...@@ -1389,6 +1417,19 @@ include $(BUILD_SYSTEM)/base_rules.mk
$(LOCAL_BUILT_MODULE): $(built_plat_pc) $(LOCAL_BUILT_MODULE): $(built_plat_pc)
$(hide) cp -f $< $@ $(hide) cp -f $< $@
##################################
include $(CLEAR_VARS)
LOCAL_MODULE := product_property_contexts.recovery
LOCAL_MODULE_STEM := product_property_contexts
LOCAL_MODULE_CLASS := ETC
LOCAL_MODULE_TAGS := optional
LOCAL_MODULE_PATH := $(TARGET_RECOVERY_ROOT_OUT)
include $(BUILD_SYSTEM)/base_rules.mk
$(LOCAL_BUILT_MODULE): $(built_product_pc)
$(hide) cp -f $< $@
################################## ##################################
include $(CLEAR_VARS) include $(CLEAR_VARS)
LOCAL_MODULE := vendor_property_contexts.recovery LOCAL_MODULE := vendor_property_contexts.recovery
...@@ -1887,6 +1928,7 @@ built_plat_cil := ...@@ -1887,6 +1928,7 @@ built_plat_cil :=
built_plat_pub_vers_cil := built_plat_pub_vers_cil :=
built_mapping_cil := built_mapping_cil :=
built_plat_pc := built_plat_pc :=
built_product_pc :=
built_vendor_cil := built_vendor_cil :=
built_vendor_pc := built_vendor_pc :=
built_vendor_sc := built_vendor_sc :=
......
...@@ -48,6 +48,7 @@ ...@@ -48,6 +48,7 @@
/nonplat_sepolicy\.cil u:object_r:sepolicy_file:s0 /nonplat_sepolicy\.cil u:object_r:sepolicy_file:s0
/plat_sepolicy\.cil u:object_r:sepolicy_file:s0 /plat_sepolicy\.cil u:object_r:sepolicy_file:s0
/plat_property_contexts u:object_r:property_contexts_file:s0 /plat_property_contexts u:object_r:property_contexts_file:s0
/product_property_contexts u:object_r:property_contexts_file:s0
/nonplat_property_contexts u:object_r:property_contexts_file:s0 /nonplat_property_contexts u:object_r:property_contexts_file:s0
/vendor_property_contexts u:object_r:property_contexts_file:s0 /vendor_property_contexts u:object_r:property_contexts_file:s0
/seapp_contexts u:object_r:seapp_contexts_file:s0 /seapp_contexts u:object_r:seapp_contexts_file:s0
...@@ -375,6 +376,7 @@ ...@@ -375,6 +376,7 @@
/(product|system/product)/etc/selinux/product_file_contexts u:object_r:file_contexts_file:s0 /(product|system/product)/etc/selinux/product_file_contexts u:object_r:file_contexts_file:s0
/(product|system/product)/etc/selinux/product_hwservice_contexts u:object_r:hwservice_contexts_file:s0 /(product|system/product)/etc/selinux/product_hwservice_contexts u:object_r:hwservice_contexts_file:s0
/(product|system/product)/etc/selinux/product_property_contexts u:object_r:property_contexts_file:s0
############################# #############################
# Product-Services files # Product-Services files
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment