Skip to content
Snippets Groups Projects
  • dcashman's avatar
    bd7f5803
    Enforce more specific service access. · bd7f5803
    dcashman authored
    Move the remaining services from tmp_system_server_service to appropriate
    attributes and remove tmp_system_server and associated logging:
    
    registry
    restrictions
    rttmanager
    scheduling_policy
    search
    sensorservice
    serial
    servicediscovery
    statusbar
    task
    textservices
    telecom_service
    trust_service
    uimode
    updatelock
    usagestats
    usb
    user
    vibrator
    voiceinteraction
    wallpaper
    webviewupdate
    wifip2p
    wifi
    window
    
    Bug: 18106000
    Change-Id: Ia0a6d47099d82c53ba403af394537db6fbc71ca0
    bd7f5803
    History
    Enforce more specific service access.
    dcashman authored
    Move the remaining services from tmp_system_server_service to appropriate
    attributes and remove tmp_system_server and associated logging:
    
    registry
    restrictions
    rttmanager
    scheduling_policy
    search
    sensorservice
    serial
    servicediscovery
    statusbar
    task
    textservices
    telecom_service
    trust_service
    uimode
    updatelock
    usagestats
    usb
    user
    vibrator
    voiceinteraction
    wallpaper
    webviewupdate
    wifip2p
    wifi
    window
    
    Bug: 18106000
    Change-Id: Ia0a6d47099d82c53ba403af394537db6fbc71ca0
attributes 1.83 KiB
######################################
# Attribute declarations
#

# All types used for devices.
attribute dev_type;

# All types used for processes.
attribute domain;

# All types used for filesystems.
attribute fs_type;

# All types used for context= mounts.
attribute contextmount_type;

# All types used for files that can exist on a labeled fs.
# Do not use for pseudo file types.
attribute file_type;

# All types used for domain entry points.
attribute exec_type;

# All types used for /data files.
attribute data_file_type;

# All types use for sysfs files.
attribute sysfs_type;

# Attribute used for all sdcards
attribute sdcard_type;

# All types used for nodes/hosts.
attribute node_type;

# All types used for network interfaces.
attribute netif_type;

# All types used for network ports.
attribute port_type;

# All types used for property service
attribute property_type;

# All service_manager types created by system_server
attribute system_server_service;

# services which should be available to all but isolated apps
attribute app_api_service;

# services which export only system_api
attribute system_api_service;

# All types used for services managed by service_manager.
attribute service_manager_type;

# All domains that can override MLS restrictions.
# i.e. processes that can read up and write down.
attribute mlstrustedsubject;

# All types that can override MLS restrictions.
# i.e. files that can be read by lower and written by higher
attribute mlstrustedobject;

# All domains used for apps.
attribute appdomain;

# All domains used for apps with network access.
attribute netdomain;
# All domains used for apps with bluetooth access.
attribute bluetoothdomain;

# All domains used for binder service domains.
attribute binderservicedomain;

# All domains that are excluded from the domain.te auditallow.
attribute service_manager_local_audit;