Skip to content
Snippets Groups Projects
Commit 3b896623 authored by Jeff Vander Stoep's avatar Jeff Vander Stoep Committed by android-build-merger
Browse files

Merge "Restrict HAL network access to HALS that manage network hardware"

am: b9b63706

Change-Id: I32c85f2ba81e8be3b0065ac0d8e737cd323f86a1
parents fa633e52 b9b63706
No related branches found
No related tags found
No related merge requests found
# only HALs responsible for network hardware should have privileged
# network capabilities
neverallow {
halserverdomain
-hal_bluetooth_server
-hal_wifi_server
-hal_wifi_supplicant_server
-rild
} self:capability { net_admin net_raw };
# Unless a HAL's job is to manage network hardware, it should not be
# using network sockets.
neverallow {
halserverdomain
-hal_gnss # TODO b/36085168 b/35757613
-hal_wifi_server
-hal_wifi_supplicant_server
-rild
} domain:{ tcp_socket udp_socket rawip_socket } *;
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment