Stephen Smalley | 2dd4e51 | 2012-01-04 12:33:27 -0500 | [diff] [blame] | 1 | # debugger interface |
Jeff Vander Stoep | d22987b | 2015-11-03 09:54:39 -0800 | [diff] [blame] | 2 | type debuggerd, domain, domain_deprecated; |
Stephen Smalley | 2dd4e51 | 2012-01-04 12:33:27 -0500 | [diff] [blame] | 3 | type debuggerd_exec, exec_type, file_type; |
| 4 | |
Stephen Smalley | 258cb17 | 2013-10-29 14:42:35 -0400 | [diff] [blame] | 5 | typeattribute debuggerd mlstrustedsubject; |
Josh Gao | 2b93db7 | 2015-11-17 16:21:38 -0800 | [diff] [blame] | 6 | allow debuggerd self:capability { dac_override sys_ptrace chown kill fowner setuid setgid }; |
Stephen Smalley | 258cb17 | 2013-10-29 14:42:35 -0400 | [diff] [blame] | 7 | allow debuggerd self:capability2 { syslog }; |
| 8 | allow debuggerd domain:dir r_dir_perms; |
| 9 | allow debuggerd domain:file r_file_perms; |
Elliott Hughes | 38138c2 | 2014-05-16 19:14:13 -0700 | [diff] [blame] | 10 | allow debuggerd domain:lnk_file read; |
Nick Kralevich | 2d6fa72 | 2016-04-27 12:32:36 -0700 | [diff] [blame] | 11 | allow debuggerd { |
| 12 | domain |
| 13 | -adbd |
| 14 | -debuggerd |
| 15 | -healthd |
| 16 | -init |
| 17 | -keystore |
Nick Kralevich | cb5f4a3 | 2016-12-05 14:01:28 -0800 | [diff] [blame^] | 18 | -logd |
Nick Kralevich | 2d6fa72 | 2016-04-27 12:32:36 -0700 | [diff] [blame] | 19 | -ueventd |
| 20 | -watchdogd |
Janis Danisevskis | 071b935 | 2016-09-14 10:00:13 +0100 | [diff] [blame] | 21 | }:process { execmem ptrace getattr }; |
Nick Kralevich | cb5f4a3 | 2016-12-05 14:01:28 -0800 | [diff] [blame^] | 22 | |
| 23 | userdebug_or_eng(` |
| 24 | allow debuggerd logd:process { execmem ptrace getattr }; |
| 25 | ') |
| 26 | |
Josh Gao | 2b93db7 | 2015-11-17 16:21:38 -0800 | [diff] [blame] | 27 | allow debuggerd tombstone_data_file:dir rw_dir_perms; |
Stephen Smalley | 258cb17 | 2013-10-29 14:42:35 -0400 | [diff] [blame] | 28 | allow debuggerd tombstone_data_file:file create_file_perms; |
dcashman | cd10eb9 | 2014-08-18 17:09:38 -0700 | [diff] [blame] | 29 | allow debuggerd shared_relro_file:dir r_dir_perms; |
| 30 | allow debuggerd shared_relro_file:file r_file_perms; |
Josh Gao | 48141c3 | 2016-03-08 18:02:15 -0800 | [diff] [blame] | 31 | allow debuggerd domain:process { sigstop sigkill signal }; |
Nick Kralevich | 364fd19 | 2016-11-08 09:08:55 -0800 | [diff] [blame] | 32 | allow debuggerd { exec_type libart_file }:file r_file_perms; |
Stephen Smalley | 258cb17 | 2013-10-29 14:42:35 -0400 | [diff] [blame] | 33 | # Access app library |
| 34 | allow debuggerd system_data_file:file open; |
Christopher Ferris | b51c4dd | 2015-01-18 17:39:53 -0800 | [diff] [blame] | 35 | # Allow debuggerd to redirect a dump_backtrace request to itself. |
| 36 | # This only happens on 64 bit systems, where all requests go to the 64 bit |
| 37 | # debuggerd and get redirected to the 32 bit debuggerd if the process is 32 bit. |
Chien-Yu Chen | e037830 | 2015-12-03 16:10:05 -0800 | [diff] [blame] | 38 | |
Andreas Gampe | 0983db4 | 2016-05-11 18:40:27 -0700 | [diff] [blame] | 39 | allow debuggerd { |
| 40 | audioserver |
Andreas Gampe | cbfa8dd | 2016-05-12 17:28:34 -0700 | [diff] [blame] | 41 | bluetooth |
Andreas Gampe | 0983db4 | 2016-05-11 18:40:27 -0700 | [diff] [blame] | 42 | cameraserver |
| 43 | drmserver |
| 44 | inputflinger |
| 45 | mediacodec |
| 46 | mediadrmserver |
| 47 | mediaextractor |
| 48 | mediaserver |
| 49 | sdcardd |
| 50 | surfaceflinger |
| 51 | }:debuggerd dump_backtrace; |
Stephen Smalley | 45ba665 | 2013-09-27 10:24:49 -0400 | [diff] [blame] | 52 | |
| 53 | # Connect to system_server via /data/system/ndebugsocket. |
| 54 | unix_socket_connect(debuggerd, system_ndebug, system_server) |
Mark Salyzyn | 8ed750e | 2013-11-12 15:34:52 -0800 | [diff] [blame] | 55 | |
Nick Kralevich | 116a20f | 2014-02-05 16:36:25 -0800 | [diff] [blame] | 56 | userdebug_or_eng(` |
| 57 | allow debuggerd input_device:dir r_dir_perms; |
| 58 | allow debuggerd input_device:chr_file rw_file_perms; |
| 59 | ') |
| 60 | |
Mark Salyzyn | 8ed750e | 2013-11-12 15:34:52 -0800 | [diff] [blame] | 61 | # logd access |
| 62 | read_logd(debuggerd) |
Stephen Smalley | ba99249 | 2014-07-24 15:25:43 -0400 | [diff] [blame] | 63 | |
| 64 | # Check SELinux permissions. |
| 65 | selinux_check_access(debuggerd) |
Jeff Vander Stoep | 7ef8073 | 2016-09-09 16:27:17 -0700 | [diff] [blame] | 66 | |
| 67 | # Read /data/dalvik-cache. |
| 68 | allow debuggerd dalvikcache_data_file:dir { search getattr }; |
| 69 | allow debuggerd dalvikcache_data_file:file r_file_perms; |