Skip to content
Snippets Groups Projects
Commit 3692b318 authored by Sandeep Patil's avatar Sandeep Patil Committed by Android (Google) Code Review
Browse files

Merge changes from topic 'fix-neverallow-violation' into oc-dev

* changes:
  build: run neverallow checks on platform sepolicy
  radio: disalllow radio and rild socket for treble devices
parents e9381d5e cfb6f352
No related branches found
No related tags found
No related merge requests found
...@@ -329,7 +329,7 @@ $(LOCAL_BUILT_MODULE): $(plat_policy.conf) $(HOST_OUT_EXECUTABLES)/checkpolicy \ ...@@ -329,7 +329,7 @@ $(LOCAL_BUILT_MODULE): $(plat_policy.conf) $(HOST_OUT_EXECUTABLES)/checkpolicy \
@mkdir -p $(dir $@) @mkdir -p $(dir $@)
$(hide) $(HOST_OUT_EXECUTABLES)/checkpolicy -M -C -c $(POLICYVERS) -o $@ $< $(hide) $(HOST_OUT_EXECUTABLES)/checkpolicy -M -C -c $(POLICYVERS) -o $@ $<
$(hide) cat $(PRIVATE_ADDITIONAL_CIL_FILES) >> $@ $(hide) cat $(PRIVATE_ADDITIONAL_CIL_FILES) >> $@
$(hide) $(HOST_OUT_EXECUTABLES)/secilc -M true -G -N -c $(POLICYVERS) $@ -o /dev/null -f /dev/null $(hide) $(HOST_OUT_EXECUTABLES)/secilc -M true -G -c $(POLICYVERS) $@ -o /dev/null -f /dev/null
built_plat_cil := $(LOCAL_BUILT_MODULE) built_plat_cil := $(LOCAL_BUILT_MODULE)
plat_policy.conf := plat_policy.conf :=
......
...@@ -5,9 +5,8 @@ net_domain(radio) ...@@ -5,9 +5,8 @@ net_domain(radio)
bluetooth_domain(radio) bluetooth_domain(radio)
binder_service(radio) binder_service(radio)
# TODO(b/36613472): Remove this once radio no longer communicates with rild over sockets. # Talks to rild via the rild socket only for devices without full treble
# Talks to rild via the rild socket. not_full_treble(`unix_socket_connect(radio, rild, rild)')
unix_socket_connect(radio, rild, rild)
# Data file accesses. # Data file accesses.
allow radio radio_data_file:dir create_dir_perms; allow radio radio_data_file:dir create_dir_perms;
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment