Skip to content
Snippets Groups Projects
  1. Dec 12, 2015
    • Nick Kralevich's avatar
      bluetoothdomain.te: drop allow bluetoothdomain self:socket create_socket_perms; · d0113ae0
      Nick Kralevich authored
      An auditallow has been in place since commit
      cb835a28 but nothing has been triggered.
      Remove the rule.
      
      Bug: 25768265
      Change-Id: Ia9f35c41feabc9ccf5eb5c6dae09c68dc4f465ff
      d0113ae0
    • Nick Kralevich's avatar
      bluetoothdomain.te: drop bluetooth unix_stream_socket auditallow · a1f903da
      Nick Kralevich authored
      Yes, it's being used.
      
        type=1400 audit(0.0:19391): avc: granted { read write } for comm="Binder_4" path="socket:[1354209]" dev="sockfs" ino=1354209 scontext=u:r:untrusted_app:s0:c512,c768 tcontext=u:r:bluetooth:s0 tclass=unix_stream_socket
        type=1400 audit(0.0:19392): avc: granted { read } for comm="pandora.android" scontext=u:r:untrusted_app:s0:c512,c768 tcontext=u:r:bluetooth:s0 tclass=unix_stream_socket
        type=1400 audit(0.0:19393): avc: granted { read } for comm="TransportReader" scontext=u:r:untrusted_app:s0:c512,c768 tcontext=u:r:bluetooth:s0 tclass=unix_stream_socket
        type=1400 audit(0.0:19398): avc: granted { shutdown } for comm="AppLinkBluetoot" scontext=u:r:untrusted_app:s0:c512,c768 tcontext=u:r:bluetooth:s0 tclass=unix_stream_socket
        type=1400 audit(0.0:19400): avc: granted { getopt } for comm="AppLinkBluetoot" scontext=u:r:untrusted_app:s0:c512,c768 tcontext=u:r:bluetooth:s0 tclass=unix_stream_socket
        type=1400 audit(0.0:12517): avc: granted { write } for comm="MultiQueueWrite" scontext=u:r:priv_app:s0:c512,c768 tcontext=u:r:bluetooth:s0 tclass=unix_stream_socket
        type=1400 audit(0.0:12563): avc: granted { read } for comm="WearableReader" scontext=u:r:priv_app:s0:c512,c768 tcontext=u:r:bluetooth:s0 tclass=unix_stream_socket
      
      and a lot more...
      
      Bug: 25767747
      Change-Id: I15f89be1f44eef471e432e6d9f9ecb60a43801f8
      a1f903da
  2. Nov 24, 2015
  3. Nov 18, 2015
    • Nick Kralevich's avatar
      Move bluetoothdomain rules into their own file. · 85dcd53b
      Nick Kralevich authored
      Don't mix bluetooth rules with bluetoothdomain. The bluetoothdomain
      rules are used by several other SELinux domains, not just bluetooth,
      and keeping them in the same file is confusing.
      
      Change-Id: I487251ab1c1392467a39c7a87328cdaf802fc1f8
      85dcd53b
Loading