mediaprovider.te 1.8 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546
  1. ###
  2. ### A domain for android.process.media, which contains both
  3. ### MediaProvider and DownloadProvider and associated services.
  4. ###
  5. typeattribute mediaprovider coredomain;
  6. app_domain(mediaprovider)
  7. # DownloadProvider accesses the network.
  8. net_domain(mediaprovider)
  9. # DownloadProvider uses /cache.
  10. allow mediaprovider cache_file:dir create_dir_perms;
  11. allow mediaprovider cache_file:file create_file_perms;
  12. # /cache is a symlink to /data/cache on some devices. Allow reading the link.
  13. allow mediaprovider cache_file:lnk_file r_file_perms;
  14. # mediaprovider searches through /cache looking for orphans
  15. # Ignore denials to /cache/recovery and /cache/backup.
  16. dontaudit mediaprovider cache_private_backup_file:dir getattr;
  17. dontaudit mediaprovider cache_recovery_file:dir getattr;
  18. # Access external sdcards through /mnt/media_rw
  19. allow mediaprovider { mnt_media_rw_file }:dir search;
  20. allow mediaprovider app_api_service:service_manager find;
  21. allow mediaprovider audioserver_service:service_manager find;
  22. allow mediaprovider drmserver_service:service_manager find;
  23. allow mediaprovider mediaextractor_service:service_manager find;
  24. allow mediaprovider mediaserver_service:service_manager find;
  25. # Allow MediaProvider to read/write cached ringtones (opened by system).
  26. allow mediaprovider ringtone_file:file { getattr read write };
  27. # MtpServer uses /dev/mtp_usb
  28. allow mediaprovider mtp_device:chr_file rw_file_perms;
  29. # MtpServer uses /dev/usb-ffs/mtp
  30. allow mediaprovider functionfs:dir search;
  31. allow mediaprovider functionfs:file rw_file_perms;
  32. allowxperm mediaprovider functionfs:file ioctl FUNCTIONFS_ENDPOINT_DESC;
  33. # MtpServer sets sys.usb.ffs.mtp.ready
  34. set_prop(mediaprovider, ffs_prop)
  35. set_prop(mediaprovider, exported_ffs_prop)
  36. allow mediaprovider ashmem_device:chr_file { getattr read ioctl lock map append write };