Move coredomain seapp ctx and types to system_ext
Coredomain apps shouldn't be labeled with vendor sepolicy, due to Treble violation. Bug: 280547417 Test: build bluejay and boot test Merged-In: I48441749de4eb1de90ce5a307b1d47ae3cb9592d Change-Id: I48441749de4eb1de90ce5a307b1d47ae3cb9592d
This commit is contained in:
parent
80c26d2524
commit
502fd30697
8 changed files with 27 additions and 32 deletions
7
system_ext/private/con_monitor.te
Normal file
7
system_ext/private/con_monitor.te
Normal file
|
@ -0,0 +1,7 @@
|
|||
typeattribute con_monitor_app coredomain;
|
||||
|
||||
app_domain(con_monitor_app)
|
||||
|
||||
set_prop(con_monitor_app, radio_prop)
|
||||
allow con_monitor_app app_api_service:service_manager find;
|
||||
allow con_monitor_app radio_service:service_manager find;
|
11
system_ext/private/hbmsvmanager_app.te
Normal file
11
system_ext/private/hbmsvmanager_app.te
Normal file
|
@ -0,0 +1,11 @@
|
|||
typeattribute hbmsvmanager_app coredomain;
|
||||
|
||||
app_domain(hbmsvmanager_app);
|
||||
|
||||
allow hbmsvmanager_app proc_vendor_sched:dir r_dir_perms;
|
||||
allow hbmsvmanager_app proc_vendor_sched:file w_file_perms;
|
||||
|
||||
# Standard system services
|
||||
allow hbmsvmanager_app app_api_service:service_manager find;
|
||||
|
||||
allow hbmsvmanager_app cameraserver_service:service_manager find;
|
|
@ -1,2 +1,8 @@
|
|||
# Domain for EuiccGoogle
|
||||
user=_app isPrivApp=true name=com.google.android.euicc domain=euicc_app type=privapp_data_file levelFrom=user
|
||||
|
||||
# Domain for connectivity monitor
|
||||
user=_app isPrivApp=true seinfo=platform name=com.google.android.connectivitymonitor domain=con_monitor_app type=app_data_file levelFrom=all
|
||||
|
||||
# HbmSVManager
|
||||
user=_app seinfo=platform name=com.android.hbmsvmanager domain=hbmsvmanager_app type=app_data_file levelFrom=all
|
||||
|
|
2
system_ext/public/con_monitor.te
Normal file
2
system_ext/public/con_monitor.te
Normal file
|
@ -0,0 +1,2 @@
|
|||
# ConnectivityMonitor app
|
||||
type con_monitor_app, domain;
|
1
system_ext/public/hbmsvmanager_app.te
Normal file
1
system_ext/public/hbmsvmanager_app.te
Normal file
|
@ -0,0 +1 @@
|
|||
type hbmsvmanager_app, domain;
|
Loading…
Add table
Add a link
Reference in a new issue