Skip to content
Snippets Groups Projects
Commit 9b3c3661 authored by Stephen Smalley's avatar Stephen Smalley Committed by Nick Kralevich
Browse files

Add a domain for mdnsd and allow connecting to it.


Signed-off-by: default avatarStephen Smalley <sds@tycho.nsa.gov>

(cherry picked from commit 96ff4c05)

Change-Id: Idfd734f07687925c1f35d2629d4b59d46822d0d4
parent d188f5be
No related branches found
No related tags found
No related merge requests found
......@@ -109,6 +109,7 @@ type installd_socket, file_type;
type keystore_socket, file_type;
type lmkd_socket, file_type;
type mdns_socket, file_type;
type mdnsd_socket, file_type;
type netd_socket, file_type;
type property_socket, file_type;
type qemud_socket, file_type;
......
......@@ -82,6 +82,7 @@
/dev/socket/keystore u:object_r:keystore_socket:s0
/dev/socket/lmkd u:object_r:lmkd_socket:s0
/dev/socket/mdns u:object_r:mdns_socket:s0
/dev/socket/mdnsd u:object_r:mdnsd_socket:s0
/dev/socket/netd u:object_r:netd_socket:s0
/dev/socket/property_service u:object_r:property_socket:s0
/dev/socket/qemud u:object_r:qemud_socket:s0
......@@ -126,6 +127,7 @@
/system/bin/netd u:object_r:netd_exec:s0
/system/bin/rild u:object_r:rild_exec:s0
/system/bin/mediaserver u:object_r:mediaserver_exec:s0
/system/bin/mdnsd u:object_r:mdnsd_exec:s0
/system/bin/installd u:object_r:installd_exec:s0
/system/bin/keystore u:object_r:keystore_exec:s0
/system/bin/debuggerd u:object_r:debuggerd_exec:s0
......
# mdns daemon
type mdnsd, domain;
permissive_or_unconfined(mdnsd)
type mdnsd_exec, exec_type, file_type;
init_daemon_domain(mdnsd)
net_domain(mdnsd)
......@@ -16,3 +16,6 @@ allow netdomain self:netlink_route_socket { create bind read nlmsg_read };
# Talks to netd via dnsproxyd socket.
unix_socket_connect(netdomain, dnsproxyd, netd)
# Connect to mdnsd via mdnsd socket.
unix_socket_connect(netdomain, mdnsd, mdnsd)
......@@ -52,7 +52,6 @@ allow netd clatd:process signal;
# Support netd running mdnsd
# TODO: prune this back further
allow netd ctl_default_prop:property_service set;
allow netd device:sock_file write;
###
### Neverallow rules
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment