common: add sepolicy for slsi tetheroffload HAL
authorFrancescodario Cuzzocrea <bosconovic@gmail.com>
Tue, 19 Mar 2024 21:22:10 +0000 (22:22 +0100)
committerFrancescodario Cuzzocrea <bosconovic@gmail.com>
Fri, 26 Apr 2024 12:41:51 +0000 (14:41 +0200)
Change-Id: I89fb4c0b1f58e8b9473d33a6bd91d1533df6f2a9
Signed-off-by: Francescodario Cuzzocrea <bosconovic@gmail.com>
common/vendor/device.te
common/vendor/file_contexts
common/vendor/hal_tetheroffload_default.te [new file with mode: 0644]

index 32626d34e7b421dde723b6802b5cc322f4179cea..7ecfa72e3875845f3cc7b6e0dd75b57aa13a5c4b 100644 (file)
@@ -13,6 +13,7 @@ type vbmeta_block_device, dev_type;
 
 type bbd_device, dev_type;
 type cpu_dma_device, dev_type;
+type dit_device, dev_type;
 type drb_device, dev_type;
 type epic_device, dev_type;
 type fp_sensor_device, dev_type;
index 3534175667020b07b39529be019b9d8565910f8c..45394cbdff62b1efb196af6f60567a7a21354bb8 100644 (file)
@@ -47,6 +47,9 @@
 # cpu
 /dev/cpu_dma_latency                         u:object_r:cpu_dma_device:s0
 
+### DIT device
+/dev/dit                                     u:object_r:dit_device:s0
+
 ### epic
 /dev/mode                                    u:object_r:epic_device:s0
 /dev/socket/epic                             u:object_r:epicd_socket:s0
 /(vendor|system/vendor)/bin/hw/vendor\.samsung\.hardware\.gnss@[0-9].[0-9]-service                u:object_r:hal_gnss_default_exec:s0
 /(vendor|system/vendor)/bin/hw/vendor\.samsung_slsi\.hardware\.configstore@[0-9]\.[0-9]-service   u:object_r:hal_vendor_configstore_default_exec:s0
 /(vendor|system/vendor)/bin/hw/vendor\.samsung_slsi\.hardware\.ExynosHWCServiceTW@[0-9]\.[0-9]-service    u:object_r:hal_vendor_hwcservice_default_exec:s0
+/(vendor|system/vendor)/bin/hw/vendor\.samsung_slsi\.hardware\.tetheroffload@[0-9]\.[0-9]-service                  u:object_r:hal_tetheroffload_default_exec:s0
 
 /(vendor|system/vendor)/firmware(/.*)?       u:object_r:vendor_firmware_file:s0
diff --git a/common/vendor/hal_tetheroffload_default.te b/common/vendor/hal_tetheroffload_default.te
new file mode 100644 (file)
index 0000000..0c0cccf
--- /dev/null
@@ -0,0 +1,19 @@
+net_domain(hal_tetheroffload_default)
+
+# Allow operations with /dev/dit
+allow hal_tetheroffload_default dit_device:chr_file rw_file_perms;
+
+# Allow receiving NETLINK messages
+allow hal_tetheroffload_default self:{
+    netlink_socket
+    netlink_generic_socket
+} create_socket_perms_no_ioctl;
+
+# Alloc check interface
+allow hal_tetheroffload_default netd:unix_dgram_socket create_socket_perms;
+allow hal_tetheroffload_default netd:unix_dgram_socket {read write};
+
+# Register to hwbinder service
+add_hwservice(hal_tetheroffload_default, hal_tetheroffload_hwservice)
+hwbinder_use(hal_tetheroffload_default)
+get_prop(hal_tetheroffload_default, hwservicemanager_prop)