Skip to content
Snippets Groups Projects
  1. Apr 24, 2017
    • Jeff Vander Stoep's avatar
      Retain neverallow rules in CIL files · b8787693
      Jeff Vander Stoep authored
      Fixes issue where attributes used exlusively in neverallow
      rules were removed from policy.
      
      For on-device compile use the -N flag to skip neverallow tests.
      
      Policy size increases:
      vendor/etc/selinux/nonplat_sepolicy.cil 547849 -> 635637
      vendor/etc/selinux/precompiled_sepolicy 440248 -> 441076
      system/etc/selinux/plat_sepolicy.cil    567664 -> 745230
      
      For a total increase in system/vendor: 266182.
      
      Boot time changes:
      Pixel uses precompiled policy so boot time is not impacted.
      When forcing on-device compile on Marlin selinux policy compile
      time increases 510-520 ms -> 550-560 ms.
      
      Bug: 37357742
      Test: Build and boot Marlin.
      Test: Verify both precompiled and on-device compile work.
      Change-Id: Ib3cb53d376a96e34f55ac27d651a6ce2fabf6ba7
      b8787693
  2. Apr 21, 2017
  3. Apr 20, 2017
  4. Apr 19, 2017
  5. Apr 18, 2017
    • Carmen Jackson's avatar
    • Carmen Jackson's avatar
      Add selinux rules for additional file contexts in userdebug · 25788df1
      Carmen Jackson authored
      These rules allow the additional tracepoints we need for running traceur
      in userdebug builds to be writeable.
      
      Bug: 37110010
      Test: I'm testing by running atrace -l and confirming that the
      tracepoints that I'm attempting to enable are available.
      
      Change-Id: Ia352100ed67819ae5acca2aad803fa392d8b80fd
      25788df1
    • Dan Cashman's avatar
      Remove vndservice_manager object classes. · 2f1c7ba7
      Dan Cashman authored
      vndservicemanager is a copy of servicemanager, and so has the exact
      same properties.  This should be reflected in the sharing of an object
      manager in SELinux policy, rather than creating a second one, which is
      effectively an attempt at namespacing based on object rather than type
      labels.  hwservicemanager, however, provides different and additional
      functionality that may be reflected in changed permissions, though they
      currently map to the existing servicemanager permissions.  Keep the new
      hwservice_manager object manager but remove the vndservice_manager one.
      
      Bug: 34454312
      Bug: 36052864
      Test: policy builds and device boots.
      Change-Id: I9e0c2757be4026101e32ba780f1fa67130cfa14e
      2f1c7ba7
    • Alex Klyubin's avatar
      surfaceflinger and apps are clients of Configstore HAL · 75ca4832
      Alex Klyubin authored
      This commit marks surfaceflinger and app domain (except isolated_app)
      as clients of Configstore HAL. This cleans up the policy and will make
      it easier to restrict access to HwBinder services later.
      
      Test: Play YouTube clip in YouTube app and YouTube web page in Chrome
      Test: Take an HDR+ photo, a normal photo, a video, and slow motion
            video in Google Camera app. Check that photos show up fine and
            that videos play back with sound.
      Test: Play movie using Google Play Movies
      Test: Google Maps app displays the Android's correct location
      Bug: 34454312
      Change-Id: I0f468a4289132f4eaacfb1d13ce4e61604c2a371
      75ca4832
  6. Apr 17, 2017
    • Alex Klyubin's avatar
      Apps and system_server are gralloc HAL clients · 5007c10a
      Alex Klyubin authored
      This commit marks system_server and app domains (except isolated_app)
      as clients of Graphics Allocator HAL. This makes the policy cleaner
      and prepares ground for restricting access to HwBinder services.
      
      Test: Play video in YouTube app and in Google Chrome YouTube web page
      Test: Using Google Camera app, take an HDR+ photo, a conventional
            photo, record a video with sound and a slow motion video with
            sound, then check that photos look good and videos play back
            fine, including sound.
      Bug: 34454312
      Change-Id: Iea04d38fa5520432f06af94570fa6ce16ed7979a
      5007c10a
    • TreeHugger Robot's avatar
  7. Apr 16, 2017
  8. Apr 15, 2017
Loading