From 8b1d45201d65116b48beec363828af9c7ae32a23 Mon Sep 17 00:00:00 2001 From: Jeff Sharkey <jsharkey@android.com> Date: Fri, 9 Dec 2016 15:39:07 -0700 Subject: [PATCH] installd has moved on to Binder; goodbye socket! After a series of recent commits, installd has fully migrated over to Binder, and all socket-based communication has been removed. Test: builds, boots, apps install fine, pre-OTA dexopt works Bug: 13758960, 30944031 Change-Id: Ia67b6260de58240d057c99b1bbd782b44376dfb5 --- private/file_contexts | 1 - public/app.te | 1 - public/file.te | 1 - public/system_server.te | 1 - 4 files changed, 4 deletions(-) diff --git a/private/file_contexts b/private/file_contexts index 4719f1054..83d179df8 100644 --- a/private/file_contexts +++ b/private/file_contexts @@ -106,7 +106,6 @@ /dev/socket/dnsproxyd u:object_r:dnsproxyd_socket:s0 /dev/socket/dumpstate u:object_r:dumpstate_socket:s0 /dev/socket/fwmarkd u:object_r:fwmarkd_socket:s0 -/dev/socket/installd u:object_r:installd_socket:s0 /dev/socket/lmkd u:object_r:lmkd_socket:s0 /dev/socket/logd u:object_r:logd_socket:s0 /dev/socket/logdr u:object_r:logdr_socket:s0 diff --git a/public/app.te b/public/app.te index ffd647efd..064b25f16 100644 --- a/public/app.te +++ b/public/app.te @@ -334,7 +334,6 @@ neverallow appdomain socket_device:sock_file write; # Unix domain sockets. neverallow appdomain adbd_socket:sock_file write; -neverallow appdomain installd_socket:sock_file write; neverallow { appdomain -radio } rild_socket:sock_file write; neverallow appdomain vold_socket:sock_file write; neverallow appdomain zygote_socket:sock_file write; diff --git a/public/file.te b/public/file.te index 57f99cb5c..80df22d76 100644 --- a/public/file.te +++ b/public/file.te @@ -217,7 +217,6 @@ type bluetooth_socket, file_type; type dnsproxyd_socket, file_type, mlstrustedobject; type dumpstate_socket, file_type; type fwmarkd_socket, file_type, mlstrustedobject; -type installd_socket, file_type; type lmkd_socket, file_type; type logd_socket, file_type, mlstrustedobject; type logdr_socket, file_type, mlstrustedobject; diff --git a/public/system_server.te b/public/system_server.te index 5d0ac0042..36e95ab8b 100644 --- a/public/system_server.te +++ b/public/system_server.te @@ -131,7 +131,6 @@ allow system_server node:rawip_socket node_bind; allow system_server self:tun_socket create_socket_perms_no_ioctl; # Talk to init and various daemons via sockets. -unix_socket_connect(system_server, installd, installd) unix_socket_connect(system_server, lmkd, lmkd) unix_socket_connect(system_server, mtpd, mtp) unix_socket_connect(system_server, netd, netd) -- GitLab