blob: 8088f3b8f3bde85819d2c71b978f1b93587bdcc6 [file] [log] [blame]
shubangf8ab3eb2020-09-11 17:50:45 -07001# mediatuner - mediatuner daemon
2type mediatuner, domain;
3type mediatuner_exec, system_file_type, exec_type, file_type;
4
5typeattribute mediatuner coredomain;
6
7init_daemon_domain(mediatuner)
8hal_client_domain(mediatuner, hal_tv_tuner)
9
10binder_use(mediatuner)
11binder_call(mediatuner, appdomain)
12binder_service(mediatuner)
13
14add_service(mediatuner, mediatuner_service)
15allow mediatuner system_server:fd use;
Amy Zhangec7079b2021-01-21 11:08:37 -080016allow mediatuner tv_tuner_resource_mgr_service:service_manager find;
17binder_call(mediatuner, system_server)
shubangf8ab3eb2020-09-11 17:50:45 -070018
19###
20### neverallow rules
21###
22
23# mediatuner should never execute any executable without a
24# domain transition
25neverallow mediatuner { file_type fs_type }:file execute_no_trans;
26
27# do not allow privileged socket ioctl commands
28neverallowxperm mediatuner domain:{ rawip_socket tcp_socket udp_socket } ioctl priv_sock_ioctls;
29