Skip to content
Snippets Groups Projects
Select Git revision
  • android-7.1.2_r28_klist
  • master default protected
  • pie-cts-release
  • pie-vts-release
  • pie-cts-dev
  • oreo-mr1-iot-release
  • sdk-release
  • oreo-m6-s4-release
  • oreo-m4-s12-release
  • pie-release
  • pie-r2-release
  • pie-r2-s1-release
  • oreo-vts-release
  • oreo-cts-release
  • oreo-dev
  • oreo-mr1-dev
  • pie-gsi
  • pie-platform-release
  • pie-dev
  • oreo-cts-dev
  • android-o-mr1-iot-release-1.0.4
  • android-9.0.0_r8
  • android-9.0.0_r7
  • android-9.0.0_r6
  • android-9.0.0_r5
  • android-8.1.0_r46
  • android-8.1.0_r45
  • android-n-iot-release-smart-display-r2
  • android-vts-8.1_r5
  • android-cts-8.1_r8
  • android-cts-8.0_r12
  • android-cts-7.1_r20
  • android-cts-7.0_r24
  • android-o-mr1-iot-release-1.0.3
  • android-cts-9.0_r1
  • android-8.1.0_r43
  • android-8.1.0_r42
  • android-n-iot-release-smart-display
  • android-p-preview-5
  • android-9.0.0_r3
40 results

hostapd.te

  • Stephen Smalley's avatar
    7ade68d7
    Ensure that /data/misc/wifi/sockets is always labeled wpa_socket. · 7ade68d7
    Stephen Smalley authored
    
    It appears that wpa_supplicant tries to rmdir /data/misc/wifi/sockets
    and re-create it at times, so make sure that it remains labeled correctly
    when re-created in this manner via a name-based type transition rule.
    Do the same for hostapd as it also has permissions for creating/removing
    this directory.
    
    <5>[83921.800071] type=1400 audit(1392997522.105:26): avc:  denied  { rmdir } for  pid=3055 comm="wpa_supplicant" name="sockets" dev="mmcblk0p28" ino=618957 scontext=u:r:wpa:s0 tcontext=u:object_r:wpa_socket:s0 tclass=dir
    
    We no longer need the type_transition for sock_file as it will inherit
    the type from the parent directory which is set via restorecon_recursive
    /data/misc/wifi/sockets or via type_transition, so drop it.
    
    Change-Id: Iffa61c426783eb03205ba6964c624c6ecea32630
    Signed-off-by: default avatarStephen Smalley <sds@tycho.nsa.gov>
    7ade68d7
    History
    Ensure that /data/misc/wifi/sockets is always labeled wpa_socket.
    Stephen Smalley authored
    
    It appears that wpa_supplicant tries to rmdir /data/misc/wifi/sockets
    and re-create it at times, so make sure that it remains labeled correctly
    when re-created in this manner via a name-based type transition rule.
    Do the same for hostapd as it also has permissions for creating/removing
    this directory.
    
    <5>[83921.800071] type=1400 audit(1392997522.105:26): avc:  denied  { rmdir } for  pid=3055 comm="wpa_supplicant" name="sockets" dev="mmcblk0p28" ino=618957 scontext=u:r:wpa:s0 tcontext=u:object_r:wpa_socket:s0 tclass=dir
    
    We no longer need the type_transition for sock_file as it will inherit
    the type from the parent directory which is set via restorecon_recursive
    /data/misc/wifi/sockets or via type_transition, so drop it.
    
    Change-Id: Iffa61c426783eb03205ba6964c624c6ecea32630
    Signed-off-by: default avatarStephen Smalley <sds@tycho.nsa.gov>