blob: 6d8eff21e5ce65c71e7799d972c689fc83a9723f [file] [log] [blame]
Stephen Smalley2dd4e512012-01-04 12:33:27 -05001LOCAL_PATH:= $(call my-dir)
William Robertsf0e0a942012-08-27 15:41:15 -07002
Stephen Smalley2dd4e512012-01-04 12:33:27 -05003include $(CLEAR_VARS)
4
5# SELinux policy version.
6# Must be <= /selinux/policyvers reported by the Android kernel.
7# Must be within the compatibility range reported by checkpolicy -V.
Stephen Smalleye543a8b2013-04-01 10:07:43 -04008POLICYVERS ?= 26
Stephen Smalley2dd4e512012-01-04 12:33:27 -05009
10MLS_SENS=1
11MLS_CATS=1024
12
rpcraig47cd3962012-10-17 21:09:52 -040013# Quick edge case error detection for BOARD_SEPOLICY_REPLACE.
14# Builds the singular path for each replace file.
15sepolicy_replace_paths :=
16$(foreach pf, $(BOARD_SEPOLICY_REPLACE), \
17 $(if $(filter $(pf), $(BOARD_SEPOLICY_UNION)), \
18 $(error Ambiguous request for sepolicy $(pf). Appears in both \
19 BOARD_SEPOLICY_REPLACE and BOARD_SEPOLICY_UNION), \
20 ) \
William Roberts15b3ced2013-02-12 13:30:47 +090021 $(eval _paths := $(filter-out $(BOARD_SEPOLICY_IGNORE), \
22 $(wildcard $(addsuffix /$(pf), $(BOARD_SEPOLICY_DIRS))))) \
rpcraig47cd3962012-10-17 21:09:52 -040023 $(eval _occurrences := $(words $(_paths))) \
24 $(if $(filter 0,$(_occurrences)), \
25 $(error No sepolicy file found for $(pf) in $(BOARD_SEPOLICY_DIRS)), \
26 ) \
27 $(if $(filter 1, $(_occurrences)), \
28 $(eval sepolicy_replace_paths += $(_paths)), \
29 $(error Multiple occurrences of replace file $(pf) in $(_paths)) \
30 ) \
31 $(if $(filter 0, $(words $(wildcard $(addsuffix /$(pf), $(LOCAL_PATH))))), \
32 $(error Specified the sepolicy file $(pf) in BOARD_SEPOLICY_REPLACE, \
33 but none found in $(LOCAL_PATH)), \
34 ) \
35)
Stephen Smalley5b340be2012-03-06 11:12:41 -050036
Robert Craig6b0ff472014-01-29 13:10:58 -050037# Quick edge case error detection for BOARD_SEPOLICY_UNION.
38# This ensures that a requested union file exists somewhere
39# in one of the listed BOARD_SEPOLICY_DIRS.
40$(foreach pf, $(BOARD_SEPOLICY_UNION), \
41 $(if $(filter 0, $(words $(wildcard $(addsuffix /$(pf), $(BOARD_SEPOLICY_DIRS))))), \
42 $(error No sepolicy file found for $(pf) in $(BOARD_SEPOLICY_DIRS)), \
43 ) \
44)
45
rpcraig47cd3962012-10-17 21:09:52 -040046# Builds paths for all requested policy files w.r.t
47# both BOARD_SEPOLICY_REPLACE and BOARD_SEPOLICY_UNION
48# product variables.
49# $(1): the set of policy name paths to build
50build_policy = $(foreach type, $(1), \
William Roberts15b3ced2013-02-12 13:30:47 +090051 $(filter-out $(BOARD_SEPOLICY_IGNORE), \
52 $(foreach expanded_type, $(notdir $(wildcard $(addsuffix /$(type), $(LOCAL_PATH)))), \
53 $(if $(filter $(expanded_type), $(BOARD_SEPOLICY_REPLACE)), \
54 $(wildcard $(addsuffix $(expanded_type), $(sort $(dir $(sepolicy_replace_paths))))), \
55 $(LOCAL_PATH)/$(expanded_type) \
56 ) \
rpcraig47cd3962012-10-17 21:09:52 -040057 ) \
William Roberts15b3ced2013-02-12 13:30:47 +090058 $(foreach union_policy, $(wildcard $(addsuffix /$(type), $(BOARD_SEPOLICY_DIRS))), \
59 $(if $(filter $(notdir $(union_policy)), $(BOARD_SEPOLICY_UNION)), \
60 $(union_policy), \
61 ) \
rpcraig47cd3962012-10-17 21:09:52 -040062 ) \
63 ) \
64)
Stephen Smalley5b340be2012-03-06 11:12:41 -050065
dcashman704741a2014-07-25 19:11:52 -070066sepolicy_build_files := security_classes \
67 initial_sids \
68 access_vectors \
69 global_macros \
Nick Kralevicha17a2662014-11-05 15:30:41 -080070 neverallow_macros \
dcashman704741a2014-07-25 19:11:52 -070071 mls_macros \
72 mls \
73 policy_capabilities \
74 te_macros \
75 attributes \
76 *.te \
77 roles \
78 users \
79 initial_sid_contexts \
80 fs_use \
81 genfs_contexts \
82 port_contexts
83
Ying Wang02fb5f32012-01-17 17:51:09 -080084##################################
85include $(CLEAR_VARS)
Stephen Smalley2dd4e512012-01-04 12:33:27 -050086
Ying Wang02fb5f32012-01-17 17:51:09 -080087LOCAL_MODULE := sepolicy
88LOCAL_MODULE_CLASS := ETC
89LOCAL_MODULE_TAGS := optional
Ying Wang02fb5f32012-01-17 17:51:09 -080090LOCAL_MODULE_PATH := $(TARGET_ROOT_OUT)
Stephen Smalley2dd4e512012-01-04 12:33:27 -050091
Ying Wang02fb5f32012-01-17 17:51:09 -080092include $(BUILD_SYSTEM)/base_rules.mk
Stephen Smalley2dd4e512012-01-04 12:33:27 -050093
Ying Wang02fb5f32012-01-17 17:51:09 -080094sepolicy_policy.conf := $(intermediates)/policy.conf
95$(sepolicy_policy.conf): PRIVATE_MLS_SENS := $(MLS_SENS)
96$(sepolicy_policy.conf): PRIVATE_MLS_CATS := $(MLS_CATS)
dcashman704741a2014-07-25 19:11:52 -070097$(sepolicy_policy.conf) : $(call build_policy, $(sepolicy_build_files))
Ying Wang02fb5f32012-01-17 17:51:09 -080098 @mkdir -p $(dir $@)
Nick Kralevich623975f2014-01-11 01:31:03 -080099 $(hide) m4 -D mls_num_sens=$(PRIVATE_MLS_SENS) -D mls_num_cats=$(PRIVATE_MLS_CATS) \
100 -D target_build_variant=$(TARGET_BUILD_VARIANT) \
Nick Kralevich623975f2014-01-11 01:31:03 -0800101 -s $^ > $@
Robert Craig65d4f442013-03-27 06:30:25 -0400102 $(hide) sed '/dontaudit/d' $@ > $@.dontaudit
Stephen Smalley2dd4e512012-01-04 12:33:27 -0500103
Stephen Smalley2b826fc2012-01-24 08:46:13 -0500104$(LOCAL_BUILT_MODULE) : $(sepolicy_policy.conf) $(HOST_OUT_EXECUTABLES)/checkpolicy
Ying Wang02fb5f32012-01-17 17:51:09 -0800105 @mkdir -p $(dir $@)
Ying Wangf4ea5b22012-04-09 15:31:03 -0700106 $(hide) $(HOST_OUT_EXECUTABLES)/checkpolicy -M -c $(POLICYVERS) -o $@ $<
Robert Craig65d4f442013-03-27 06:30:25 -0400107 $(hide) $(HOST_OUT_EXECUTABLES)/checkpolicy -M -c $(POLICYVERS) -o $(dir $<)/$(notdir $@).dontaudit $<.dontaudit
Ying Wang02fb5f32012-01-17 17:51:09 -0800108
Ying Wangd8b122c2012-10-25 19:01:31 -0700109built_sepolicy := $(LOCAL_BUILT_MODULE)
Ying Wang02fb5f32012-01-17 17:51:09 -0800110sepolicy_policy.conf :=
Stephen Smalley01a58af2012-10-02 12:46:37 -0400111
Stephen Smalleye60723a2014-05-29 16:40:15 -0400112##################################
113include $(CLEAR_VARS)
114
115LOCAL_MODULE := sepolicy.recovery
116LOCAL_MODULE_CLASS := ETC
117LOCAL_MODULE_TAGS := eng
118
119include $(BUILD_SYSTEM)/base_rules.mk
120
121sepolicy_policy_recovery.conf := $(intermediates)/policy_recovery.conf
122$(sepolicy_policy_recovery.conf): PRIVATE_MLS_SENS := $(MLS_SENS)
123$(sepolicy_policy_recovery.conf): PRIVATE_MLS_CATS := $(MLS_CATS)
dcashman704741a2014-07-25 19:11:52 -0700124$(sepolicy_policy_recovery.conf) : $(call build_policy, $(sepolicy_build_files))
Stephen Smalleye60723a2014-05-29 16:40:15 -0400125 @mkdir -p $(dir $@)
126 $(hide) m4 -D mls_num_sens=$(PRIVATE_MLS_SENS) -D mls_num_cats=$(PRIVATE_MLS_CATS) \
127 -D target_build_variant=$(TARGET_BUILD_VARIANT) \
Stephen Smalleye60723a2014-05-29 16:40:15 -0400128 -D target_recovery=true \
129 -s $^ > $@
130
131$(LOCAL_BUILT_MODULE) : $(sepolicy_policy_recovery.conf) $(HOST_OUT_EXECUTABLES)/checkpolicy
132 @mkdir -p $(dir $@)
133 $(hide) $(HOST_OUT_EXECUTABLES)/checkpolicy -M -c $(POLICYVERS) -o $@ $<
134
135built_sepolicy_recovery := $(LOCAL_BUILT_MODULE)
136sepolicy_policy_recovery.conf :=
137
dcashman704741a2014-07-25 19:11:52 -0700138##################################
139include $(CLEAR_VARS)
140
141LOCAL_MODULE := general_sepolicy.conf
142LOCAL_MODULE_CLASS := ETC
143LOCAL_MODULE_TAGS := tests
144
145include $(BUILD_SYSTEM)/base_rules.mk
146
147exp_sepolicy_build_files :=\
148 $(wildcard $(addprefix $(LOCAL_PATH)/, $(sepolicy_build_files)))
149
150$(LOCAL_BUILT_MODULE): PRIVATE_MLS_SENS := $(MLS_SENS)
151$(LOCAL_BUILT_MODULE): PRIVATE_MLS_CATS := $(MLS_CATS)
152$(LOCAL_BUILT_MODULE): $(exp_sepolicy_build_files)
153 mkdir -p $(dir $@)
154 $(hide) m4 -D mls_num_sens=$(PRIVATE_MLS_SENS) -D mls_num_cats=$(PRIVATE_MLS_CATS) \
155 -D target_build_variant=user \
dcashman704741a2014-07-25 19:11:52 -0700156 -s $^ > $@
157 $(hide) sed '/dontaudit/d' $@ > $@.dontaudit
158
159GENERAL_SEPOLICY_POLICY.CONF = $(LOCAL_BUILT_MODULE)
160
161exp_sepolicy_build_files :=
162
163##################################
Stephen Smalley01a58af2012-10-02 12:46:37 -0400164include $(CLEAR_VARS)
165
Ying Wang02fb5f32012-01-17 17:51:09 -0800166LOCAL_MODULE := file_contexts
Ying Wang02fb5f32012-01-17 17:51:09 -0800167LOCAL_MODULE_CLASS := ETC
168LOCAL_MODULE_TAGS := optional
169LOCAL_MODULE_PATH := $(TARGET_ROOT_OUT)
170
Stephen Smalley5b340be2012-03-06 11:12:41 -0500171include $(BUILD_SYSTEM)/base_rules.mk
Ying Wang02fb5f32012-01-17 17:51:09 -0800172
rpcraig47cd3962012-10-17 21:09:52 -0400173ALL_FC_FILES := $(call build_policy, file_contexts)
Stephen Smalley01a58af2012-10-02 12:46:37 -0400174
Ying Wangd8b122c2012-10-25 19:01:31 -0700175$(LOCAL_BUILT_MODULE): PRIVATE_SEPOLICY := $(built_sepolicy)
176$(LOCAL_BUILT_MODULE): $(ALL_FC_FILES) $(built_sepolicy) $(HOST_OUT_EXECUTABLES)/checkfc
Stephen Smalley5b340be2012-03-06 11:12:41 -0500177 @mkdir -p $(dir $@)
Stephen Smalley01a58af2012-10-02 12:46:37 -0400178 $(hide) m4 -s $(ALL_FC_FILES) > $@
Ying Wangd8b122c2012-10-25 19:01:31 -0700179 $(hide) $(HOST_OUT_EXECUTABLES)/checkfc $(PRIVATE_SEPOLICY) $@
Stephen Smalley5b340be2012-03-06 11:12:41 -0500180
Robert Craig8b7545b2014-03-20 09:35:08 -0400181built_fc := $(LOCAL_BUILT_MODULE)
William Roberts171a0622012-08-16 10:55:05 -0700182
Ying Wang02fb5f32012-01-17 17:51:09 -0800183##################################
184include $(CLEAR_VARS)
Ying Wang02fb5f32012-01-17 17:51:09 -0800185LOCAL_MODULE := seapp_contexts
Ying Wang02fb5f32012-01-17 17:51:09 -0800186LOCAL_MODULE_CLASS := ETC
187LOCAL_MODULE_TAGS := optional
188LOCAL_MODULE_PATH := $(TARGET_ROOT_OUT)
189
William Roberts171a0622012-08-16 10:55:05 -0700190include $(BUILD_SYSTEM)/base_rules.mk
Ying Wang02fb5f32012-01-17 17:51:09 -0800191
William Roberts98ed3922012-09-05 11:19:07 -0700192seapp_contexts.tmp := $(intermediates)/seapp_contexts.tmp
rpcraig47cd3962012-10-17 21:09:52 -0400193$(seapp_contexts.tmp): $(call build_policy, seapp_contexts)
William Roberts171a0622012-08-16 10:55:05 -0700194 @mkdir -p $(dir $@)
195 $(hide) m4 -s $^ > $@
196
Ying Wangd8b122c2012-10-25 19:01:31 -0700197$(LOCAL_BUILT_MODULE): PRIVATE_SEPOLICY := $(built_sepolicy)
198$(LOCAL_BUILT_MODULE) : $(seapp_contexts.tmp) $(built_sepolicy) $(HOST_OUT_EXECUTABLES)/checkseapp
William Robertsf0e0a942012-08-27 15:41:15 -0700199 @mkdir -p $(dir $@)
Ying Wangd8b122c2012-10-25 19:01:31 -0700200 $(HOST_OUT_EXECUTABLES)/checkseapp -p $(PRIVATE_SEPOLICY) -o $@ $<
Ying Wang02fb5f32012-01-17 17:51:09 -0800201
Robert Craig8b7545b2014-03-20 09:35:08 -0400202built_sc := $(LOCAL_BUILT_MODULE)
William Roberts98ed3922012-09-05 11:19:07 -0700203seapp_contexts.tmp :=
Robert Craig8b7545b2014-03-20 09:35:08 -0400204
Ying Wang02fb5f32012-01-17 17:51:09 -0800205##################################
Stephen Smalley124720a2012-04-04 10:11:16 -0400206include $(CLEAR_VARS)
Stephen Smalley37712872015-03-12 15:46:36 -0400207LOCAL_MODULE := general_seapp_contexts
208LOCAL_MODULE_CLASS := ETC
209LOCAL_MODULE_TAGS := tests
210
211include $(BUILD_SYSTEM)/base_rules.mk
212
213general_seapp_contexts.tmp := $(intermediates)/general_seapp_contexts.tmp
214$(general_seapp_contexts.tmp): $(addprefix $(LOCAL_PATH)/, seapp_contexts)
215 @mkdir -p $(dir $@)
216 $(hide) m4 -s $^ > $@
217
218$(LOCAL_BUILT_MODULE): PRIVATE_SEPOLICY := $(built_sepolicy)
219$(LOCAL_BUILT_MODULE) : $(general_seapp_contexts.tmp) $(built_sepolicy) $(HOST_OUT_EXECUTABLES)/checkseapp
220 @mkdir -p $(dir $@)
221 $(HOST_OUT_EXECUTABLES)/checkseapp -p $(PRIVATE_SEPOLICY) -o $@ $<
222
223GENERAL_SEAPP_CONTEXTS := $(LOCAL_BUILT_MODULE)
224general_seapp_contexts.tmp :=
225
226##################################
227include $(CLEAR_VARS)
Stephen Smalley124720a2012-04-04 10:11:16 -0400228
229LOCAL_MODULE := property_contexts
230LOCAL_MODULE_CLASS := ETC
231LOCAL_MODULE_TAGS := optional
232LOCAL_MODULE_PATH := $(TARGET_ROOT_OUT)
233
234include $(BUILD_SYSTEM)/base_rules.mk
235
Robert Craigd98d26e2013-01-23 14:04:50 -0500236ALL_PC_FILES := $(call build_policy, property_contexts)
237
238$(LOCAL_BUILT_MODULE): PRIVATE_SEPOLICY := $(built_sepolicy)
239$(LOCAL_BUILT_MODULE): $(ALL_PC_FILES) $(built_sepolicy) $(HOST_OUT_EXECUTABLES)/checkfc
Stephen Smalley124720a2012-04-04 10:11:16 -0400240 @mkdir -p $(dir $@)
Robert Craigd98d26e2013-01-23 14:04:50 -0500241 $(hide) m4 -s $(ALL_PC_FILES) > $@
242 $(hide) $(HOST_OUT_EXECUTABLES)/checkfc -p $(PRIVATE_SEPOLICY) $@
Stephen Smalley124720a2012-04-04 10:11:16 -0400243
Robert Craig8b7545b2014-03-20 09:35:08 -0400244built_pc := $(LOCAL_BUILT_MODULE)
245
Stephen Smalley124720a2012-04-04 10:11:16 -0400246##################################
Riley Spahnf90c41f2014-06-05 15:52:02 -0700247include $(CLEAR_VARS)
248
249LOCAL_MODULE := service_contexts
250LOCAL_MODULE_CLASS := ETC
251LOCAL_MODULE_TAGS := optional
252LOCAL_MODULE_PATH := $(TARGET_ROOT_OUT)
253
254include $(BUILD_SYSTEM)/base_rules.mk
255
256ALL_SVC_FILES := $(call build_policy, service_contexts)
257
258$(LOCAL_BUILT_MODULE): PRIVATE_SEPOLICY := $(built_sepolicy)
259$(LOCAL_BUILT_MODULE): $(ALL_SVC_FILES) $(built_sepolicy) $(HOST_OUT_EXECUTABLES)/checkfc
260 @mkdir -p $(dir $@)
261 $(hide) m4 -s $(ALL_SVC_FILES) > $@
262 $(hide) $(HOST_OUT_EXECUTABLES)/checkfc -p $(PRIVATE_SEPOLICY) $@
263
264built_svc := $(LOCAL_BUILT_MODULE)
265
266##################################
rpcraigb19665c2012-07-30 09:33:03 -0400267include $(CLEAR_VARS)
268
Robert Craig7f2392e2013-03-27 08:35:39 -0400269LOCAL_MODULE := mac_permissions.xml
rpcraigb19665c2012-07-30 09:33:03 -0400270LOCAL_MODULE_CLASS := ETC
271LOCAL_MODULE_TAGS := optional
272LOCAL_MODULE_PATH := $(TARGET_OUT_ETC)/security
273
William Roberts2c8a55d2012-11-30 14:59:09 -0800274include $(BUILD_SYSTEM)/base_rules.mk
rpcraigb19665c2012-07-30 09:33:03 -0400275
Geremy Condracd4104e2013-03-26 18:19:12 +0000276# Build keys.conf
277mac_perms_keys.tmp := $(intermediates)/keys.tmp
278$(mac_perms_keys.tmp) : $(call build_policy, keys.conf)
279 @mkdir -p $(dir $@)
280 $(hide) m4 -s $^ > $@
281
Robert Craig7f2392e2013-03-27 08:35:39 -0400282ALL_MAC_PERMS_FILES := $(call build_policy, $(LOCAL_MODULE))
rpcraigb19665c2012-07-30 09:33:03 -0400283
Robert Craig7f2392e2013-03-27 08:35:39 -0400284$(LOCAL_BUILT_MODULE) : $(mac_perms_keys.tmp) $(HOST_OUT_EXECUTABLES)/insertkeys.py $(ALL_MAC_PERMS_FILES)
Geremy Condracd4104e2013-03-26 18:19:12 +0000285 @mkdir -p $(dir $@)
Nick Kralevichc3c90522013-10-25 12:25:36 -0700286 $(hide) DEFAULT_SYSTEM_DEV_CERTIFICATE="$(dir $(DEFAULT_SYSTEM_DEV_CERTIFICATE))" \
287 $(HOST_OUT_EXECUTABLES)/insertkeys.py -t $(TARGET_BUILD_VARIANT) -c $(TOP) $< -o $@ $(ALL_MAC_PERMS_FILES)
Geremy Condracd4104e2013-03-26 18:19:12 +0000288
Robert Craig7f2392e2013-03-27 08:35:39 -0400289mac_perms_keys.tmp :=
rpcraigb19665c2012-07-30 09:33:03 -0400290##################################
Robert Craig8b7545b2014-03-20 09:35:08 -0400291include $(CLEAR_VARS)
292
293LOCAL_MODULE := selinux_version
294LOCAL_MODULE_CLASS := ETC
295LOCAL_MODULE_TAGS := optional
296LOCAL_MODULE_PATH := $(TARGET_ROOT_OUT)
297
298include $(BUILD_SYSTEM)/base_rules.mk
Riley Spahnf90c41f2014-06-05 15:52:02 -0700299$(LOCAL_BUILT_MODULE) : $(built_sepolicy) $(built_pc) $(built_fc) $(built_sc) $(built_svc)
Robert Craig8b7545b2014-03-20 09:35:08 -0400300 @mkdir -p $(dir $@)
301 $(hide) echo -n $(BUILD_FINGERPRINT) > $@
302
303##################################
rpcraig47cd3962012-10-17 21:09:52 -0400304
305build_policy :=
dcashman704741a2014-07-25 19:11:52 -0700306sepolicy_build_files :=
rpcraig47cd3962012-10-17 21:09:52 -0400307sepolicy_replace_paths :=
Robert Craig8b7545b2014-03-20 09:35:08 -0400308built_sepolicy :=
309built_sc :=
310built_fc :=
311built_pc :=
Riley Spahnf90c41f2014-06-05 15:52:02 -0700312built_svc :=
Alice Chucdfb06f2012-11-01 11:33:04 -0700313
314include $(call all-makefiles-under,$(LOCAL_PATH))