diff options
author | Boxiang Pan <bopan@codeaurora.org> | 2014-10-31 18:01:46 -0700 |
---|---|---|
committer | Avijit Kanti Das <avijitnsec@codeaurora.org> | 2014-11-03 14:24:09 -0800 |
commit | bd05645e5594c61c66413ce08c06cc5624207c52 (patch) | |
tree | 088527546603450d6e96796fbbdcdd49cc2f933e /common | |
parent | 42a58192e0f08c95d63667df67b7f46f3037eea6 (diff) | |
download | android_device_qcom_sepolicy-bd05645e5594c61c66413ce08c06cc5624207c52.tar.gz android_device_qcom_sepolicy-bd05645e5594c61c66413ce08c06cc5624207c52.tar.bz2 android_device_qcom_sepolicy-bd05645e5594c61c66413ce08c06cc5624207c52.zip |
sepolicy: add rule for CNE.
add rule for CNE data file for db file
Change-Id: I1dbc81f7be2bb4b4344336546622d351f5fa3e23
Diffstat (limited to 'common')
-rw-r--r-- | common/cnd.te | 1 | ||||
-rw-r--r-- | common/netd.te | 1 | ||||
-rw-r--r-- | common/system_app.te | 2 |
3 files changed, 4 insertions, 0 deletions
diff --git a/common/cnd.te b/common/cnd.te index 1cfc90c9..86ab50a9 100644 --- a/common/cnd.te +++ b/common/cnd.te @@ -20,6 +20,7 @@ allow cnd self:netlink_tcpdiag_socket { bind create write read nlmsg_read getopt}; allow cnd self:netlink_route_socket { read bind create write nlmsg_read }; +allow cnd self:netlink_socket { create setopt getopt bind getattr write read }; # allow cnd to set system property allow cnd system_prop:property_service set; diff --git a/common/netd.te b/common/netd.te index cfdc509d..a5e70fa9 100644 --- a/common/netd.te +++ b/common/netd.te @@ -6,3 +6,4 @@ dontaudit netd self:capability sys_module; #needed for ipt_TCPMSS and ip6t_TCPMSS allow netd kernel:system module_request; +unix_socket_connect(netd, cnd, cnd) diff --git a/common/system_app.te b/common/system_app.te index 4a7de392..895cec2f 100644 --- a/common/system_app.te +++ b/common/system_app.te @@ -18,3 +18,5 @@ allow system_app cne_service:service_manager add; userdebug_or_eng(` allow system_app debugfs:file r_file_perms; ') +allow system_app cnd_data_file:dir w_dir_perms; +allow system_app cnd_data_file:file create_file_perms; |