Merge changes from topic "260522282" into udc-d1-dev

* changes:
  Revert^2 "Enforce priv_app"
  Label ims_remote_app and rcs_service_app
This commit is contained in:
Wilson Sung 2023-04-20 02:46:06 +00:00 committed by Android (Google) Code Review
commit f4a5867e2a
4 changed files with 12 additions and 21 deletions

View file

@ -14,7 +14,10 @@ user=_app isPrivApp=true name=com.google.android.grilservice domain=grilservice_
user=_app isPrivApp=true name=com.samsung.slsi.telephony.oemril domain=oemrilservice_app levelFrom=all
user=_app isPrivApp=true name=com.shannon.qualifiednetworksservice domain=vendor_qualifiednetworks_app levelFrom=all
user=_app isPrivApp=true name=com.shannon.rcsservice domain=vendor_rcs_app levelFrom=all
user=_app isPrivApp=true name=com.shannon.rcsservice:shannonrcsservice domain=vendor_rcs_service_app levelFrom=all
user=_app isPrivApp=true name=com.shannon.imsservice domain=vendor_ims_app levelFrom=all
user=_app isPrivApp=true name=com.shannon.imsservice:remote domain=vendor_ims_remote_app levelFrom=all
# slsi logging apps
user=system seinfo=platform name=com.samsung.slsi.telephony.silentlogging domain=vendor_telephony_silentlogging_app levelFrom=all

View file

@ -0,0 +1,4 @@
type vendor_ims_remote_app, domain;
app_domain(vendor_ims_remote_app)
allow vendor_ims_remote_app app_api_service:service_manager find;

View file

@ -0,0 +1,5 @@
type vendor_rcs_service_app, domain;
app_domain(vendor_rcs_service_app)
allow vendor_rcs_service_app app_api_service:service_manager find;
allow vendor_rcs_service_app radio_service:service_manager find;

View file

@ -1,21 +0,0 @@
# b/260366281
dontaudit priv_app privapp_data_file:dir { getattr };
dontaudit priv_app privapp_data_file:dir { search };
dontaudit priv_app vendor_default_prop:file { getattr };
dontaudit priv_app vendor_default_prop:file { map };
dontaudit priv_app vendor_default_prop:file { open };
# b/260522282
dontaudit priv_app privapp_data_file:file { open };
dontaudit priv_app privapp_data_file:file { setattr };
# b/260768358
dontaudit priv_app default_android_service:service_manager { find };
# b/260922442
dontaudit priv_app default_android_service:service_manager { find };
# b/263185432
dontaudit priv_app privapp_data_file:file { unlink };
# b/264490074
userdebug_or_eng(`
permissive priv_app;
')# b/268572216
dontaudit priv_app privapp_data_file:dir { add_name };
dontaudit priv_app privapp_data_file:dir { remove_name };