Skip to content
GitLab
Explore
Sign in
Primary navigation
Search or go to…
Project
S
sepolicy
Manage
Activity
Members
Plan
Wiki
Code
Repository
Branches
Commits
Tags
Repository graph
Compare revisions
Snippets
Deploy
Releases
Package Registry
Model registry
Operate
Terraform modules
Analyze
Contributor analytics
Repository analytics
Model experiments
Help
Help
Support
GitLab documentation
Compare GitLab plans
Community forum
Contribute to GitLab
Provide feedback
Keyboard shortcuts
?
Snippets
Groups
Projects
Show more breadcrumbs
CodeLinaro
public-release-test
platform
system
sepolicy
Commits
b4c10e98
Commit
b4c10e98
authored
10 years ago
by
Nick Kralevich
Committed by
Gerrit Code Review
10 years ago
Browse files
Options
Downloads
Plain Diff
Merge "More MLS trusted subject/object annotations."
parents
a10bfd88
cbc5279a
No related branches found
No related tags found
No related merge requests found
Changes
4
Hide whitespace changes
Inline
Side-by-side
Showing
4 changed files
device.te
+5
-5
5 additions, 5 deletions
device.te
dumpstate.te
+1
-1
1 addition, 1 deletion
dumpstate.te
file.te
+8
-8
8 additions, 8 deletions
file.te
lmkd.te
+1
-1
1 addition, 1 deletion
lmkd.te
with
15 additions
and
15 deletions
device.te
+
5
−
5
View file @
b4c10e98
...
@@ -28,16 +28,16 @@ type nfc_device, dev_type;
...
@@ -28,16 +28,16 @@ type nfc_device, dev_type;
type ptmx_device, dev_type, mlstrustedobject;
type ptmx_device, dev_type, mlstrustedobject;
type kmsg_device, dev_type;
type kmsg_device, dev_type;
type null_device, dev_type, mlstrustedobject;
type null_device, dev_type, mlstrustedobject;
type random_device, dev_type;
type random_device, dev_type
, mlstrustedobject
;
type sensors_device, dev_type;
type sensors_device, dev_type;
type serial_device, dev_type;
type serial_device, dev_type;
type socket_device, dev_type;
type socket_device, dev_type;
type owntty_device, dev_type, mlstrustedobject;
type owntty_device, dev_type, mlstrustedobject;
type tty_device, dev_type;
type tty_device, dev_type;
type urandom_device, dev_type;
type urandom_device, dev_type
, mlstrustedobject
;
type video_device, dev_type;
type video_device, dev_type;
type vcs_device, dev_type;
type vcs_device, dev_type;
type zero_device, dev_type;
type zero_device, dev_type
, mlstrustedobject
;
type fuse_device, dev_type;
type fuse_device, dev_type;
type iio_device, dev_type;
type iio_device, dev_type;
type ion_device, dev_type, mlstrustedobject;
type ion_device, dev_type, mlstrustedobject;
...
@@ -47,8 +47,8 @@ type watchdog_device, dev_type;
...
@@ -47,8 +47,8 @@ type watchdog_device, dev_type;
type uhid_device, dev_type;
type uhid_device, dev_type;
type uio_device, dev_type;
type uio_device, dev_type;
type tun_device, dev_type, mlstrustedobject;
type tun_device, dev_type, mlstrustedobject;
type usbaccessory_device, dev_type;
type usbaccessory_device, dev_type
, mlstrustedobject
;
type usb_device, dev_type;
type usb_device, dev_type
, mlstrustedobject
;
type klog_device, dev_type;
type klog_device, dev_type;
type properties_device, dev_type;
type properties_device, dev_type;
...
...
This diff is collapsed.
Click to expand it.
dumpstate.te
+
1
−
1
View file @
b4c10e98
# dumpstate
# dumpstate
type dumpstate, domain;
type dumpstate, domain
, mlstrustedsubject
;
type dumpstate_exec, exec_type, file_type;
type dumpstate_exec, exec_type, file_type;
init_daemon_domain(dumpstate)
init_daemon_domain(dumpstate)
...
...
This diff is collapsed.
Click to expand it.
file.te
+
8
−
8
View file @
b4c10e98
...
@@ -12,7 +12,7 @@ type qtaguid_proc, fs_type, mlstrustedobject;
...
@@ -12,7 +12,7 @@ type qtaguid_proc, fs_type, mlstrustedobject;
type proc_bluetooth_writable, fs_type;
type proc_bluetooth_writable, fs_type;
type proc_net, fs_type;
type proc_net, fs_type;
type proc_sysrq, fs_type;
type proc_sysrq, fs_type;
type selinuxfs, fs_type;
type selinuxfs, fs_type
, mlstrustedobject
;
type cgroup, fs_type, mlstrustedobject;
type cgroup, fs_type, mlstrustedobject;
type sysfs, fs_type, sysfs_type, mlstrustedobject;
type sysfs, fs_type, sysfs_type, mlstrustedobject;
type sysfs_writable, fs_type, sysfs_type, mlstrustedobject;
type sysfs_writable, fs_type, sysfs_type, mlstrustedobject;
...
@@ -62,11 +62,11 @@ type apk_private_tmp_file, file_type, data_file_type, mlstrustedobject;
...
@@ -62,11 +62,11 @@ type apk_private_tmp_file, file_type, data_file_type, mlstrustedobject;
# /data/dalvik-cache
# /data/dalvik-cache
type dalvikcache_data_file, file_type, data_file_type;
type dalvikcache_data_file, file_type, data_file_type;
# /data/dalvik-cache/profiles
# /data/dalvik-cache/profiles
type dalvikcache_profiles_data_file, file_type, data_file_type;
type dalvikcache_profiles_data_file, file_type, data_file_type
, mlstrustedobject
;
# /data/resource-cache
# /data/resource-cache
type resourcecache_data_file, file_type, data_file_type;
type resourcecache_data_file, file_type, data_file_type;
# /data/local - writable by shell
# /data/local - writable by shell
type shell_data_file, file_type, data_file_type;
type shell_data_file, file_type, data_file_type
, mlstrustedobject
;
# /data/gps
# /data/gps
type gps_data_file, file_type, data_file_type;
type gps_data_file, file_type, data_file_type;
# /data/property
# /data/property
...
@@ -79,10 +79,10 @@ type bluetooth_data_file, file_type, data_file_type;
...
@@ -79,10 +79,10 @@ type bluetooth_data_file, file_type, data_file_type;
type camera_data_file, file_type, data_file_type;
type camera_data_file, file_type, data_file_type;
type keystore_data_file, file_type, data_file_type;
type keystore_data_file, file_type, data_file_type;
type media_data_file, file_type, data_file_type;
type media_data_file, file_type, data_file_type;
type media_rw_data_file, file_type, data_file_type;
type media_rw_data_file, file_type, data_file_type
, mlstrustedobject
;
type net_data_file, file_type, data_file_type;
type net_data_file, file_type, data_file_type;
type nfc_data_file, file_type, data_file_type;
type nfc_data_file, file_type, data_file_type;
type radio_data_file, file_type, data_file_type;
type radio_data_file, file_type, data_file_type
, mlstrustedobject
;
type shared_relro_file, file_type, data_file_type;
type shared_relro_file, file_type, data_file_type;
type systemkeys_data_file, file_type, data_file_type;
type systemkeys_data_file, file_type, data_file_type;
type vpn_data_file, file_type, data_file_type;
type vpn_data_file, file_type, data_file_type;
...
@@ -131,12 +131,12 @@ type fwmarkd_socket, file_type, mlstrustedobject;
...
@@ -131,12 +131,12 @@ type fwmarkd_socket, file_type, mlstrustedobject;
type gps_socket, file_type;
type gps_socket, file_type;
type installd_socket, file_type;
type installd_socket, file_type;
type lmkd_socket, file_type;
type lmkd_socket, file_type;
type logd_debug, file_type;
type logd_debug, file_type
, mlstrustedobject
;
type logd_socket, file_type;
type logd_socket, file_type
, mlstrustedobject
;
type logdr_socket, file_type, mlstrustedobject;
type logdr_socket, file_type, mlstrustedobject;
type logdw_socket, file_type, mlstrustedobject;
type logdw_socket, file_type, mlstrustedobject;
type mdns_socket, file_type;
type mdns_socket, file_type;
type mdnsd_socket, file_type;
type mdnsd_socket, file_type
, mlstrustedobject
;
type mtpd_socket, file_type;
type mtpd_socket, file_type;
type netd_socket, file_type;
type netd_socket, file_type;
type property_socket, file_type;
type property_socket, file_type;
...
...
This diff is collapsed.
Click to expand it.
lmkd.te
+
1
−
1
View file @
b4c10e98
# lmkd low memory killer daemon
# lmkd low memory killer daemon
type lmkd, domain;
type lmkd, domain
, mlstrustedsubject
;
type lmkd_exec, exec_type, file_type;
type lmkd_exec, exec_type, file_type;
init_daemon_domain(lmkd)
init_daemon_domain(lmkd)
...
...
This diff is collapsed.
Click to expand it.
Preview
0%
Loading
Try again
or
attach a new file
.
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Save comment
Cancel
Please
register
or
sign in
to comment