summaryrefslogtreecommitdiff
path: root/sepolicy/system_server.te
diff options
context:
space:
mode:
authorHyejin Kim <hyejin.kim@lge.com>2015-03-26 20:15:10 +0900
committerPatrick Tjin <pattjin@google.com>2015-04-09 11:25:26 -0700
commitc15ba1cbf3542c81bd90d6cb72de2234e0b2e961 (patch)
treee224b9bd21fc8c9b474ec75c950a6d32610af764 /sepolicy/system_server.te
parent95ac445dcc02f69e881cf47716bba4aaf6d7c00d (diff)
downloadbullhead-c15ba1cbf3542c81bd90d6cb72de2234e0b2e961.tar.gz
Enable radio, data related-daemons
- Enable daemons listed below rmt_storage, bridgemgrd, qmuxd, netmgrd, per_mgr - Execute IRSC utility - Add sepolicy TE files and context for daemons Change-Id: Id811e8c266876e9d1b018844b05491b7a8a0a2d4
Diffstat (limited to 'sepolicy/system_server.te')
-rw-r--r--sepolicy/system_server.te23
1 files changed, 23 insertions, 0 deletions
diff --git a/sepolicy/system_server.te b/sepolicy/system_server.te
new file mode 100644
index 0000000..a0b727f
--- /dev/null
+++ b/sepolicy/system_server.te
@@ -0,0 +1,23 @@
+# Grant access to Qualcomm MSM Interface (QMI) radio sockets to system services
+# (e.g., LocationManager)
+qmux_socket(system_server)
+
+# PowerManagerService access to sensors socket
+#unix_socket_connect(system_server, sensors, sensors)
+#unix_socket_send(system_server, sensors, sensors)
+#allow system_server sensors:unix_stream_socket sendto;
+#allow system_server sensors_socket:sock_file r_file_perms;
+
+# mpdecision socket access
+#unix_socket_connect(system_server, mpdecision, mpdecision)
+#unix_socket_send(system_server, mpdecision, mpdecision)
+#allow system_server mpdecision:unix_stream_socket sendto;
+#allow system_server mpdecision_socket:dir search;
+
+# Read /data/tombstones/ramdump files.
+#allow system_server ramdump_data_file:dir r_dir_perms;
+#allow system_server ramdump_data_file:file r_file_perms;
+
+allow system_server self:netlink_socket create_socket_perms;
+
+allow system_server rtc:chr_file rw_file_perms;