Skip to content
Snippets Groups Projects
Commit 603bc205 authored by Riley Spahn's avatar Riley Spahn
Browse files

Further refined service_manager auditallow statements.

Further refined auditallow statements associated with
service_manager and added dumpstate to the
service_manager_local_audit_domain.

Change-Id: I2ecc42c8660de6a91f3b4e56268344fbd069ccc0
parent 26d6371c
No related branches found
No related tags found
No related merge requests found
...@@ -54,6 +54,7 @@ service_manager_local_audit_domain(bluetooth) ...@@ -54,6 +54,7 @@ service_manager_local_audit_domain(bluetooth)
auditallow bluetooth { auditallow bluetooth {
service_manager_type service_manager_type
-bluetooth_service -bluetooth_service
-radio_service
-system_server_service -system_server_service
}:service_manager find; }:service_manager find;
......
...@@ -49,4 +49,8 @@ allow drmserver drmserver_service:service_manager add; ...@@ -49,4 +49,8 @@ allow drmserver drmserver_service:service_manager add;
# Audited locally. # Audited locally.
service_manager_local_audit_domain(drmserver) service_manager_local_audit_domain(drmserver)
auditallow drmserver { service_manager_type -drmserver_service }:service_manager find; auditallow drmserver {
service_manager_type
-drmserver_service
-system_server_service
}:service_manager find;
...@@ -96,3 +96,18 @@ control_logd(dumpstate) ...@@ -96,3 +96,18 @@ control_logd(dumpstate)
# Read network state info files. # Read network state info files.
allow dumpstate net_data_file:dir search; allow dumpstate net_data_file:dir search;
allow dumpstate net_data_file:file r_file_perms; allow dumpstate net_data_file:file r_file_perms;
service_manager_local_audit_domain(dumpstate)
auditallow dumpstate {
service_manager_type
-drmserver_service
-healthd_service
-inputflinger_service
-keystore_service
-mediaserver_service
-nfc_service
-radio_service
-surfaceflinger_service
-system_app_service
-system_server_service
}:service_manager find;
...@@ -21,4 +21,9 @@ allow isolated_app app_data_file:file execute; ...@@ -21,4 +21,9 @@ allow isolated_app app_data_file:file execute;
# Audited locally. # Audited locally.
service_manager_local_audit_domain(isolated_app) service_manager_local_audit_domain(isolated_app)
auditallow isolated_app service_manager_type:service_manager find; auditallow isolated_app {
service_manager_type
-radio_service
-surfaceflinger_service
-system_server_service
}:service_manager find;
...@@ -21,5 +21,6 @@ service_manager_local_audit_domain(nfc) ...@@ -21,5 +21,6 @@ service_manager_local_audit_domain(nfc)
auditallow nfc { auditallow nfc {
service_manager_type service_manager_type
-mediaserver_service -mediaserver_service
-surfaceflinger_service
-system_server_service -system_server_service
}:service_manager find; }:service_manager find;
...@@ -35,5 +35,6 @@ auditallow radio { ...@@ -35,5 +35,6 @@ auditallow radio {
service_manager_type service_manager_type
-mediaserver_service -mediaserver_service
-radio_service -radio_service
-surfaceflinger_service
-system_server_service -system_server_service
}:service_manager find; }:service_manager find;
...@@ -69,7 +69,9 @@ control_logd(system_app) ...@@ -69,7 +69,9 @@ control_logd(system_app)
service_manager_local_audit_domain(system_app) service_manager_local_audit_domain(system_app)
auditallow system_app { auditallow system_app {
service_manager_type service_manager_type
-keystore_service
-nfc_service -nfc_service
-radio_service
-surfaceflinger_service -surfaceflinger_service
-system_server_service -system_server_service
}:service_manager find; }:service_manager find;
...@@ -69,6 +69,7 @@ service_manager_local_audit_domain(untrusted_app) ...@@ -69,6 +69,7 @@ service_manager_local_audit_domain(untrusted_app)
auditallow untrusted_app { auditallow untrusted_app {
service_manager_type service_manager_type
-drmserver_service -drmserver_service
-keystore_service
-mediaserver_service -mediaserver_service
-nfc_service -nfc_service
-radio_service -radio_service
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment