Skip to content
Snippets Groups Projects
Commit f6375971 authored by Jeff Vander Stoep's avatar Jeff Vander Stoep
Browse files

wifi_supplicant: refactor permissions

1. remove some duplicate permissions.
2. Grant permissions to su for dgram sockets in a way that is
   consistent to how we grant permissions to stream_sockets.

Bug: 34980020
Test: build
Change-Id: I50e01d51444a70ead3ef40b52eda8eb29732b46c
parent dd7e36c0
No related branches found
No related tags found
No related merge requests found
...@@ -33,10 +33,9 @@ allow domain self:unix_stream_socket { create_stream_socket_perms connectto }; ...@@ -33,10 +33,9 @@ allow domain self:unix_stream_socket { create_stream_socket_perms connectto };
allow domain init:fd use; allow domain init:fd use;
userdebug_or_eng(` userdebug_or_eng(`
# Same as adbd rules above, except allow su to do the same thing
allow domain su:unix_stream_socket connectto;
allow domain su:fd use; allow domain su:fd use;
allow domain su:unix_stream_socket { getattr getopt read write shutdown }; allow domain su:unix_stream_socket { connectto getattr getopt read write shutdown };
allow domain su:unix_dgram_socket sendto;
allow { domain -init } su:binder { call transfer }; allow { domain -init } su:binder { call transfer };
......
...@@ -26,12 +26,6 @@ allow hal_wifi_supplicant wifi_data_file:file create_file_perms; ...@@ -26,12 +26,6 @@ allow hal_wifi_supplicant wifi_data_file:file create_file_perms;
allow hal_wifi_supplicant wpa_socket:dir create_dir_perms; allow hal_wifi_supplicant wpa_socket:dir create_dir_perms;
allow hal_wifi_supplicant wpa_socket:sock_file create_file_perms; allow hal_wifi_supplicant wpa_socket:sock_file create_file_perms;
# Allow wpa_cli to work. wpa_cli creates a socket in
# /data/misc/wifi/sockets which hal_wifi_supplicant supplicant communicates with.
userdebug_or_eng(`
unix_socket_send(hal_wifi_supplicant, wpa, su)
')
### ###
### neverallow rules ### neverallow rules
### ###
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment