Merge "Pass privapp specifier for selinux labeling"

This commit is contained in:
Jeffrey Vander Stoep
2015-10-14 21:33:59 +00:00
committed by Gerrit Code Review

View File

@@ -100,6 +100,9 @@ public final class SELinuxMMAC {
private static final String SEAPP_HASH_FILE =
Environment.getDataDirectory().toString() + "/system/seapp_hash";
// Append privapp to existing seinfo label
private static final String PRIVILEGED_APP_STR = ":privapp";
/**
* Load the mac_permissions.xml file containing all seinfo assignments used to
* label apps. The loaded mac_permissions.xml file is determined by the
@@ -313,6 +316,9 @@ public final class SELinuxMMAC {
}
}
if (pkg.applicationInfo.isPrivilegedApp())
pkg.applicationInfo.seinfo += PRIVILEGED_APP_STR;
if (DEBUG_POLICY_INSTALL) {
Slog.i(TAG, "package (" + pkg.packageName + ") labeled with " +
"seinfo=" + pkg.applicationInfo.seinfo);