Skip to content
Snippets Groups Projects
Commit f3a05203 authored by Jeffrey Vander Stoep's avatar Jeffrey Vander Stoep Committed by Android (Google) Code Review
Browse files

Merge "autoplay_app: access to services and other permissions"

parents 003eddfc b7baa7fd
No related branches found
No related tags found
No related merge requests found
...@@ -22,6 +22,9 @@ tmpfs_domain(autoplay_app) ...@@ -22,6 +22,9 @@ tmpfs_domain(autoplay_app)
# Map with PROT_EXEC. # Map with PROT_EXEC.
allow autoplay_app autoplay_app_tmpfs:file execute; allow autoplay_app autoplay_app_tmpfs:file execute;
# Read system properties managed by zygote.
allow autoplay_app zygote_tmpfs:file read;
# Send logcat messages to logd. # Send logcat messages to logd.
write_logd(autoplay_app) write_logd(autoplay_app)
...@@ -81,6 +84,18 @@ allow autoplay_app system_data_file:lnk_file read; ...@@ -81,6 +84,18 @@ allow autoplay_app system_data_file:lnk_file read;
# System file accesses. Check for libraries # System file accesses. Check for libraries
allow autoplay_app system_file:dir getattr; allow autoplay_app system_file:dir getattr;
# services
allow autoplay_app accessibility_service:service_manager find;
allow autoplay_app activity_service:service_manager find;
allow autoplay_app assetatlas_service:service_manager find;
allow autoplay_app connectivity_service:service_manager find;
allow autoplay_app display_service:service_manager find;
allow autoplay_app graphicsstats_service:service_manager find;
allow autoplay_app input_method_service:service_manager find;
allow autoplay_app input_service:service_manager find;
allow autoplay_app surfaceflinger_service:service_manager find;
allow autoplay_app textservices_service:service_manager find;
### ###
### neverallow rules ### neverallow rules
### ###
...@@ -97,3 +112,6 @@ neverallow autoplay_app debugfs:file read; ...@@ -97,3 +112,6 @@ neverallow autoplay_app debugfs:file read;
# execute gpu_device # execute gpu_device
neverallow autoplay_app gpu_device:chr_file execute; neverallow autoplay_app gpu_device:chr_file execute;
# access files in /sys with the default sysfs label
neverallow autoplay_app sysfs:file *;
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment