Skip to content
GitLab
Explore
Sign in
Primary navigation
Search or go to…
Project
A
AndroidSystemSEPolicy
Manage
Activity
Members
Code
Repository
Branches
Commits
Tags
Repository graph
Compare revisions
Deploy
Releases
Container Registry
Model registry
Analyze
Contributor analytics
Repository analytics
Model experiments
Help
Help
Support
GitLab documentation
Compare GitLab plans
Community forum
Contribute to GitLab
Provide feedback
Terms and privacy
Keyboard shortcuts
?
Snippets
Groups
Projects
Show more breadcrumbs
Werner Sembach
AndroidSystemSEPolicy
Commits
0e4e784c
Commit
0e4e784c
authored
7 years ago
by
TreeHugger Robot
Committed by
Android (Google) Code Review
7 years ago
Browse files
Options
Downloads
Plain Diff
Merge "Allow PackageManager to create a new service" into oc-mr1-dev
parents
e772a5cf
8bb80471
No related branches found
No related tags found
No related merge requests found
Changes
4
Hide whitespace changes
Inline
Side-by-side
Showing
4 changed files
prebuilts/api/26.0/26.0.ignore.cil
+1
-0
1 addition, 0 deletions
prebuilts/api/26.0/26.0.ignore.cil
private/service_contexts
+1
-0
1 addition, 0 deletions
private/service_contexts
private/storaged.te
+3
-0
3 additions, 0 deletions
private/storaged.te
public/service.te
+1
-0
1 addition, 0 deletions
public/service.te
with
6 additions
and
0 deletions
prebuilts/api/26.0/26.0.ignore.cil
+
1
−
0
View file @
0e4e784c
...
...
@@ -13,6 +13,7 @@
kmsg_debug_device
mediaprovider_tmpfs
netd_stable_secret_prop
package_native_service
sysfs_fs_ext4_features
system_net_netd_hwservice
thermal_service
...
...
This diff is collapsed.
Click to expand it.
private/service_contexts
+
1
−
0
View file @
0e4e784c
...
...
@@ -108,6 +108,7 @@ oem_lock u:object_r:oem_lock_service:s0
otadexopt u:object_r:otadexopt_service:s0
overlay u:object_r:overlay_service:s0
package u:object_r:package_service:s0
package_native u:object_r:package_native_service:s0
permission u:object_r:permission_service:s0
persistent_data_block u:object_r:persistent_data_block_service:s0
phone_msim u:object_r:radio_service:s0
...
...
This diff is collapsed.
Click to expand it.
private/storaged.te
+
3
−
0
View file @
0e4e784c
...
...
@@ -43,6 +43,9 @@ binder_call(storaged, healthd)
# Implements a dumpsys interface.
allow storaged dumpstate:fd use;
# use a subset of the package manager service
allow storaged package_native_service:service_manager find;
# Kernel does extra check on CAP_DAC_OVERRIDE for libbinder when storaged is
# running as root. See b/35323867 #3.
dontaudit storaged self:capability dac_override;
...
...
This diff is collapsed.
Click to expand it.
public/service.te
+
1
−
0
View file @
0e4e784c
...
...
@@ -102,6 +102,7 @@ type oem_lock_service, system_api_service, system_server_service, service_manage
type otadexopt_service, system_server_service, service_manager_type;
type overlay_service, system_api_service, system_server_service, service_manager_type;
type package_service, app_api_service, ephemeral_app_api_service, system_server_service, service_manager_type;
type package_native_service, system_server_service, service_manager_type;
type permission_service, app_api_service, ephemeral_app_api_service, system_server_service, service_manager_type;
type persistent_data_block_service, system_api_service, system_server_service, service_manager_type;
type pinner_service, system_server_service, service_manager_type;
...
...
This diff is collapsed.
Click to expand it.
Preview
0%
Loading
Try again
or
attach a new file
.
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Save comment
Cancel
Please
register
or
sign in
to comment