android_system_sepolicy/vendor
Jeff Vander Stoep 41a2abfc0d Properly Treble-ize tmpfs access
This is being done in preparation for the migration from ashmem to
memfd. In order for tmpfs objects to be usable across the Treble
boundary, they need to be declared in public policy whereas, they're
currently all declared in private policy as part of the
tmpfs_domain() macro. Remove the type declaration from the
macro, and remove tmpfs_domain() from the init_daemon_domain() macro
to avoid having to declare the *_tmpfs types for all init launched
domains. tmpfs is mostly used by apps and the media frameworks.

Bug: 122854450
Test: Boot Taimen and blueline. Watch videos, make phone calls, browse
internet, send text, install angry birds...play angry birds, keep
playing angry birds...

Change-Id: I20a47d2bb22e61b16187015c7bc7ca10accf6358
Merged-In: I20a47d2bb22e61b16187015c7bc7ca10accf6358
(cherry picked from commit e16fb9109c)
2019-01-26 17:30:41 +00:00
..
file_contexts Allow lazy HAL to run 2019-01-23 15:29:05 -08:00
file.te sepolicy(hostapd): Add a HIDL interface for hostapd 2018-05-04 21:36:24 +00:00
hal_atrace_default.te Add atrace HAL 1.0 sepolicy 2018-09-27 23:18:29 +00:00
hal_audio_default.te hal_audio_default: allow audioserver fd for status dump 2018-09-14 13:50:44 -07:00
hal_audiocontrol_default.te Move automotive HALs sepolicy to system/ 2018-05-04 21:36:48 +00:00
hal_authsecret_default.te authsecret HAL policies. 2018-02-05 11:19:46 +00:00
hal_bluetooth_btlinux.te btlinux: Move HAL definitions from system/bt 2018-06-27 23:56:31 +00:00
hal_bluetooth_default.te sepolicy: make exec_types in /vendor a subset of vendor_file_type 2017-04-11 17:20:36 +00:00
hal_bootctl_default.te sepolicy: make exec_types in /vendor a subset of vendor_file_type 2017-04-11 17:20:36 +00:00
hal_broadcastradio_default.te Move Broadcast Radio HAL to a separate binary. 2017-09-15 10:16:48 -07:00
hal_camera_default.te Ensure taking a bugreport generates no denials. 2018-03-08 02:25:18 +00:00
hal_cas_default.te Use hidl memory from allocator in CAS 2018-12-17 22:49:18 +00:00
hal_configstore_default.te sepolicy: make exec_types in /vendor a subset of vendor_file_type 2017-04-11 17:20:36 +00:00
hal_confirmationui_default.te Added default policy for Confirmation UI HAL 2018-01-24 10:22:40 -08:00
hal_contexthub_default.te sepolicy: make exec_types in /vendor a subset of vendor_file_type 2017-04-11 17:20:36 +00:00
hal_drm_default.te mediacodec->mediacodec+hal_omx{,_server,_client} 2018-05-30 18:12:32 +00:00
hal_dumpstate_default.te sepolicy: make exec_types in /vendor a subset of vendor_file_type 2017-04-11 17:20:36 +00:00
hal_evs_default.te Move automotive HALs sepolicy to system/ 2018-05-04 21:36:48 +00:00
hal_face_default.te Added placeholder SELinux policy for the biometric face HAL. 2018-12-28 12:23:56 -08:00
hal_fingerprint_default.te Remove unnecessary attributes 2017-04-14 09:39:19 -07:00
hal_gatekeeper_default.te sepolicy: make exec_types in /vendor a subset of vendor_file_type 2017-04-11 17:20:36 +00:00
hal_gnss_default.te More granular vendor access to /system files. 2018-09-20 03:07:50 +00:00
hal_graphics_allocator_default.te Properly Treble-ize tmpfs access 2019-01-26 17:30:41 +00:00
hal_graphics_composer_default.te Dontaudit denials caused by race with labeling. 2018-02-14 17:07:13 -08:00
hal_health_default.te sepolicy: make exec_types in /vendor a subset of vendor_file_type 2017-04-11 17:20:36 +00:00
hal_health_storage_default.te health.filesystem HAL renamed to health.storage 2018-09-20 04:12:45 +00:00
hal_input_classifier_default.te Permissions for InputClassifier HAL 2019-01-11 02:08:19 +00:00
hal_ir_default.te sepolicy: make exec_types in /vendor a subset of vendor_file_type 2017-04-11 17:20:36 +00:00
hal_keymaster_default.te Adding ability for hal keymaster to read vendor SPL 2018-05-11 16:51:58 +00:00
hal_light_default.te sepolicy: make exec_types in /vendor a subset of vendor_file_type 2017-04-11 17:20:36 +00:00
hal_lowpan_default.te Sync internal master and AOSP sepolicy. 2017-09-26 14:38:47 -07:00
hal_memtrack_default.te sepolicy: make exec_types in /vendor a subset of vendor_file_type 2017-04-11 17:20:36 +00:00
hal_nfc_default.te NFC HAL no longer violates socket access restrictions 2017-04-27 17:21:42 +00:00
hal_power_default.te sepolicy: make exec_types in /vendor a subset of vendor_file_type 2017-04-11 17:20:36 +00:00
hal_power_stats_default.te Add power.stats HAL 1.0 sepolicy 2018-12-11 00:11:08 +00:00
hal_radio_config_default.te Add sepolicy for radio.config 2018-01-24 12:13:10 -08:00
hal_radio_default.te Add sepolicy for radio sap 1.2 2018-04-16 12:00:11 -07:00
hal_secure_element_default.te Add secure_element_device 2018-03-07 13:54:21 -08:00
hal_sensors_default.te Add input_device permission to hal_sensors_default 2018-08-21 18:20:54 +00:00
hal_tetheroffload_default.te Sync internal master and AOSP sepolicy. 2017-09-26 14:38:47 -07:00
hal_thermal_default.te sepolicy: make exec_types in /vendor a subset of vendor_file_type 2017-04-11 17:20:36 +00:00
hal_tv_cec_default.te Make hal_tv_cec_default exec a vendor_file_type 2017-04-13 17:32:43 -07:00
hal_tv_input_default.te sepolicy: make exec_types in /vendor a subset of vendor_file_type 2017-04-11 17:20:36 +00:00
hal_usb_default.te sepolicy: make exec_types in /vendor a subset of vendor_file_type 2017-04-11 17:20:36 +00:00
hal_vehicle_default.te Move automotive HALs sepolicy to system/ 2018-05-04 21:36:48 +00:00
hal_vibrator_default.te sepolicy: make exec_types in /vendor a subset of vendor_file_type 2017-04-11 17:20:36 +00:00
hal_vr_default.te sepolicy: make exec_types in /vendor a subset of vendor_file_type 2017-04-11 17:20:36 +00:00
hal_wifi_default.te sepolicy: make exec_types in /vendor a subset of vendor_file_type 2017-04-11 17:20:36 +00:00
hal_wifi_hostapd_default.te sepolicy(hostapd): Add a HIDL interface for hostapd 2018-05-04 21:36:24 +00:00
hal_wifi_offload_default.te SE Policy for Wifi Offload HAL 2017-05-18 09:49:55 -07:00
hal_wifi_supplicant_default.te Allow wpa_supplicant to write to files in /proc/net. 2018-05-03 15:28:48 +00:00
mediacodec.te add mediaswcodec service 2018-10-11 15:10:17 -07:00
rild.te Revert "Revert "Move rild from public to vendor."" 2018-03-12 13:13:39 -07:00
tee.te sepolicy: Add rules for non-init namespaces 2017-11-21 08:34:32 -07:00
vendor_modprobe.te sepolicy: Add rules for non-init namespaces 2017-11-21 08:34:32 -07:00
vndservice_contexts Add default label and mapping for vendor services 2017-04-28 14:56:57 -07:00
vndservicemanager.te Prevent vendor_init from using binder or sockets 2018-02-09 19:32:59 +00:00