Skip to content
Snippets Groups Projects
Commit 8af4e9cb authored by dcashman's avatar dcashman
Browse files

Record observed service accesses.

Get ready to switch system_server service lookups into enforcing.

Bug: 18106000
Change-Id: Iefd4b2eee6cdd680f5ab423d15cc72a2a30e27cf
parent d9128a45
No related branches found
No related tags found
No related merge requests found
...@@ -70,6 +70,7 @@ auditallow bluetooth { ...@@ -70,6 +70,7 @@ auditallow bluetooth {
-network_management_service -network_management_service
-power_service -power_service
-registry_service -registry_service
-user_service
}:service_manager find; }:service_manager find;
# already open bugreport file descriptors may be shared with # already open bugreport file descriptors may be shared with
......
...@@ -18,6 +18,8 @@ allow isolated_app app_data_file:file { read write getattr }; ...@@ -18,6 +18,8 @@ allow isolated_app app_data_file:file { read write getattr };
allow isolated_app activity_service:service_manager find; allow isolated_app activity_service:service_manager find;
allow isolated_app display_service:service_manager find; allow isolated_app display_service:service_manager find;
service_manager_local_audit_domain(isolated_app)
##### #####
##### Neverallow ##### Neverallow
##### #####
......
...@@ -87,10 +87,12 @@ allow mediaserver tmp_system_server_service:service_manager find; ...@@ -87,10 +87,12 @@ allow mediaserver tmp_system_server_service:service_manager find;
service_manager_local_audit_domain(mediaserver) service_manager_local_audit_domain(mediaserver)
auditallow mediaserver { auditallow mediaserver {
tmp_system_server_service tmp_system_server_service
-activity_service
-appops_service -appops_service
-batterystats_service -batterystats_service
-permission_service -permission_service
-power_service -power_service
-processinfo_service
-scheduling_policy_service -scheduling_policy_service
}:service_manager find; }:service_manager find;
......
...@@ -40,6 +40,7 @@ auditallow nfc { ...@@ -40,6 +40,7 @@ auditallow nfc {
-dropbox_service -dropbox_service
-network_management_service -network_management_service
-power_service -power_service
-registry_service
-trust_service -trust_service
-user_service -user_service
-vibrator_service -vibrator_service
......
...@@ -69,10 +69,14 @@ auditallow platform_app { ...@@ -69,10 +69,14 @@ auditallow platform_app {
-power_service -power_service
-registry_service -registry_service
-search_service -search_service
-sensorservice_service
-statusbar_service -statusbar_service
-trust_service -trust_service
-uimode_service
-usb_service
-user_service -user_service
-vibrator_service -vibrator_service
-wallpaper_service -wallpaper_service
-webviewupdate_service
-wifi_service -wifi_service
}:service_manager find; }:service_manager find;
...@@ -40,13 +40,19 @@ allow radio tmp_system_server_service:service_manager find; ...@@ -40,13 +40,19 @@ allow radio tmp_system_server_service:service_manager find;
service_manager_local_audit_domain(radio) service_manager_local_audit_domain(radio)
auditallow radio { auditallow radio {
tmp_system_server_service tmp_system_server_service
-accessibility_service
-account_service
-activity_service -activity_service
-appops_service -appops_service
-assetatlas_service
-bluetooth_manager_service -bluetooth_manager_service
-connectivity_service -connectivity_service
-content_service -content_service
-country_detector_service
-display_service -display_service
-dropbox_service -dropbox_service
-imms_service
-input_method_service
-netstats_service -netstats_service
-network_management_service -network_management_service
-notification_service -notification_service
...@@ -54,5 +60,6 @@ auditallow radio { ...@@ -54,5 +60,6 @@ auditallow radio {
-registry_service -registry_service
-trust_service -trust_service
-user_service -user_service
-vibrator_service
-wifi_service -wifi_service
}:service_manager find; }:service_manager find;
...@@ -60,6 +60,7 @@ service_manager_local_audit_domain(system_app) ...@@ -60,6 +60,7 @@ service_manager_local_audit_domain(system_app)
auditallow system_app { auditallow system_app {
tmp_system_server_service tmp_system_server_service
-accessibility_service -accessibility_service
-account_service
-activity_service -activity_service
-appops_service -appops_service
-appwidget_service -appwidget_service
...@@ -73,17 +74,24 @@ auditallow system_app { ...@@ -73,17 +74,24 @@ auditallow system_app {
-display_service -display_service
-dreams_service -dreams_service
-dropbox_service -dropbox_service
-fingerprint_service
-graphicsstats_service -graphicsstats_service
-input_method_service -input_method_service
-input_service -input_service
-lock_settings_service -lock_settings_service
-media_session_service
-mount_service -mount_service
-netstats_service
-network_management_service -network_management_service
-network_score_service
-notification_service -notification_service
-power_service -power_service
-print_service -print_service
-registry_service -registry_service
-restrictions_service
-sensorservice_service -sensorservice_service
-textservices_service
-uimode_service
-usagestats_service -usagestats_service
-usb_service -usb_service
-user_service -user_service
......
...@@ -397,6 +397,7 @@ auditallow system_server { ...@@ -397,6 +397,7 @@ auditallow system_server {
-bluetooth_manager_service -bluetooth_manager_service
-connectivity_service -connectivity_service
-content_service -content_service
-country_detector_service
-device_policy_service -device_policy_service
-display_service -display_service
-dreams_service -dreams_service
...@@ -412,6 +413,7 @@ auditallow system_server { ...@@ -412,6 +413,7 @@ auditallow system_server {
-media_router_service -media_router_service
-media_session_service -media_session_service
-mount_service -mount_service
-netpolicy_service
-network_management_service -network_management_service
-network_score_service -network_score_service
-notification_service -notification_service
......
...@@ -98,14 +98,18 @@ auditallow untrusted_app { ...@@ -98,14 +98,18 @@ auditallow untrusted_app {
-battery_service -battery_service
-batterystats_service -batterystats_service
-bluetooth_manager_service -bluetooth_manager_service
-clipboard_service
-connectivity_service -connectivity_service
-content_service -content_service
-country_detector_service -country_detector_service
-default_android_service -default_android_service
-device_policy_service -device_policy_service
-diskstats_service
-display_service -display_service
-dropbox_service -dropbox_service
-graphicsstats_service -graphicsstats_service
-healthd_service
-imms_service
-input_method_service -input_method_service
-input_service -input_service
-jobscheduler_service -jobscheduler_service
...@@ -123,13 +127,16 @@ auditallow untrusted_app { ...@@ -123,13 +127,16 @@ auditallow untrusted_app {
-notification_service -notification_service
-persistent_data_block_service -persistent_data_block_service
-power_service -power_service
-procstats_service
-registry_service -registry_service
-rttmanager_service
-search_service -search_service
-sensorservice_service -sensorservice_service
-statusbar_service -statusbar_service
-textservices_service -textservices_service
-trust_service -trust_service
-uimode_service -uimode_service
-usagestats_service
-user_service -user_service
-vibrator_service -vibrator_service
-voiceinteraction_service -voiceinteraction_service
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment