Skip to content
Snippets Groups Projects
Commit cae2a062 authored by Alex Klyubin's avatar Alex Klyubin Committed by android-build-merger
Browse files

Merge "No access to tee domain over Unix domain sockets" into oc-dev am: ea53e29f

am: 3a994615

Change-Id: Ib3d15ed7b190be7410bff218cc1d97742a750267
parents 46fd679b 3a994615
Branches
Tags
No related merge requests found
......@@ -60,7 +60,6 @@ r_dir_file(surfaceflinger, dumpstate)
# Needed on some devices for playing DRM protected content,
# but seems expected and appropriate for all devices.
allow surfaceflinger tee:unix_stream_socket connectto;
allow surfaceflinger tee_device:chr_file rw_file_perms;
......
......@@ -31,7 +31,6 @@ type drmserver_socket, file_type;
# Clearly, /data/app is the most logical place to create a socket. Not.
allow drmserver apk_data_file:dir rw_dir_perms;
allow drmserver drmserver_socket:sock_file create_file_perms;
allow drmserver tee:unix_stream_socket connectto;
# Delete old socket file if present.
allow drmserver apk_data_file:sock_file unlink;
......
......@@ -34,8 +34,6 @@ allow hal_drm media_data_file:file { getattr read };
allow hal_drm sysfs:file r_file_perms;
# Connect to tee service.
allow hal_drm tee:unix_stream_socket connectto;
allow hal_drm tee_device:chr_file rw_file_perms;
# only allow unprivileged socket ioctl commands
......
......@@ -2,6 +2,4 @@
binder_call(hal_keymaster_client, hal_keymaster_server)
allow hal_keymaster tee_device:chr_file rw_file_perms;
allow hal_keymaster tee:unix_stream_socket connectto;
allow hal_keymaster ion_device:chr_file r_file_perms;
......@@ -78,9 +78,6 @@ unix_socket_connect(mediaserver, drmserver, drmserver)
# but seems appropriate for all devices.
unix_socket_connect(mediaserver, bluetooth, bluetooth)
# Connect to tee service.
allow mediaserver tee:unix_stream_socket connectto;
add_service(mediaserver, mediaserver_service)
allow mediaserver activity_service:service_manager find;
allow mediaserver appops_service:service_manager find;
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please to comment