Skip to content
Snippets Groups Projects
Commit 8cd400d3 authored by Stephen Smalley's avatar Stephen Smalley
Browse files

Move tlcd_sock policy over to manta.


Change-Id: I7d5a5f964133177e7d466b9759fcf6300fec345d
Signed-off-by: default avatarStephen Smalley <sds@tycho.nsa.gov>
parent ba1a7315
No related branches found
No related tags found
No related merge requests found
...@@ -25,16 +25,8 @@ allow drmserver { app_data_file asec_apk_file }:file { read write getattr }; ...@@ -25,16 +25,8 @@ allow drmserver { app_data_file asec_apk_file }:file { read write getattr };
allow drmserver sdcard_type:file { read write getattr }; allow drmserver sdcard_type:file { read write getattr };
r_dir_file(drmserver, efs_file) r_dir_file(drmserver, efs_file)
type drmserver_socket, file_type; # Connect to tee service.
# /data/app/tlcd_sock socket file.
# Clearly, /data/app is the most logical place to create a socket. Not.
allow drmserver apk_data_file:dir rw_dir_perms;
type_transition drmserver apk_data_file:sock_file drmserver_socket;
allow drmserver drmserver_socket:sock_file create_file_perms;
allow drmserver tee:unix_stream_socket connectto; allow drmserver tee:unix_stream_socket connectto;
# Delete old socket file if present.
allow drmserver apk_data_file:sock_file unlink;
# After taking a video, drmserver looks at the video file. # After taking a video, drmserver looks at the video file.
r_dir_file(drmserver, media_rw_data_file) r_dir_file(drmserver, media_rw_data_file)
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment