blob: c8051e142f8f8e17439cc638ca7bc6f54b5107d1 [file] [log] [blame]
Alex Klyubin75ca4832017-04-17 13:08:44 -07001# HwBinder IPC from client to server
2binder_call(hal_configstore_client, hal_configstore_server)
Alex Klyubin53656c12017-04-13 19:05:27 -07003
Dan Cashman91d398d2017-09-26 12:58:29 -07004allow hal_configstore_client hal_configstore_ISurfaceFlingerConfigs:hwservice_manager find;
5
Alex Klyubin53656c12017-04-13 19:05:27 -07006add_hwservice(hal_configstore_server, hal_configstore_ISurfaceFlingerConfigs)
7# As opposed to the rules of most other HALs, the different services exposed by
8# this HAL should be restricted to different clients. Thus, the allow rules for
9# clients are defined in the .te files of the clients.
Dan Cashman91d398d2017-09-26 12:58:29 -070010
11# hal_configstore runs with a strict seccomp filter. Use crash_dump's
12# fallback path to collect crash data.
13crash_dump_fallback(hal_configstore_server)
14
15###
16### neverallow rules
17###
18
19# Should never execute an executable without a domain transition
20neverallow hal_configstore_server { file_type fs_type }:file execute_no_trans;
21
22# Should never need network access. Disallow sockets except for
23# for unix stream/dgram sockets used for logging/debugging.
24neverallow hal_configstore_server domain:{
25 rawip_socket tcp_socket udp_socket
26 netlink_route_socket netlink_selinux_socket
27 socket netlink_socket packet_socket key_socket appletalk_socket
28 netlink_tcpdiag_socket netlink_nflog_socket
29 netlink_xfrm_socket netlink_audit_socket
30 netlink_dnrt_socket netlink_kobject_uevent_socket tun_socket
31 netlink_iscsi_socket netlink_fib_lookup_socket netlink_connector_socket
32 netlink_netfilter_socket netlink_generic_socket netlink_scsitransport_socket
33 netlink_rdma_socket netlink_crypto_socket
34} *;
35neverallow hal_configstore_server {
36 domain
37 -hal_configstore_server
38 -logd
39 userdebug_or_eng(`-su')
40 -tombstoned
41}:{ unix_dgram_socket unix_stream_socket } *;
42
43# Should never need access to anything on /data
44neverallow hal_configstore_server {
45 data_file_type
46 -anr_data_file # for crash dump collection
47 -tombstone_data_file # for crash dump collection
48 -zoneinfo_data_file # granted to domain
49}:{ file fifo_file sock_file } *;
50
51# Should never need sdcard access
Jeff Sharkey000cafc2018-03-30 12:22:54 -060052neverallow hal_configstore_server {
53 sdcard_type
54 fuse sdcardfs vfat exfat # manual expansion for completeness
55}:dir ~getattr;
56neverallow hal_configstore_server {
57 sdcard_type
58 fuse sdcardfs vfat exfat # manual expansion for completeness
59}:file *;
Dan Cashman91d398d2017-09-26 12:58:29 -070060
61# Do not permit access to service_manager and vndservice_manager
62neverallow hal_configstore_server *:service_manager *;
63
64# No privileged capabilities
65neverallow hal_configstore_server self:capability_class_set *;
66
67# No ptracing other processes
68neverallow hal_configstore_server *:process ptrace;
69
70# no relabeling
71neverallow hal_configstore_server *:dir_file_class_set { relabelfrom relabelto };