blob: fd454bf957e4d4fe93455795ad492a30093ac32d [file] [log] [blame]
Stephen Smalley2dd4e512012-01-04 12:33:27 -05001# wpa - wpa supplicant or equivalent
2type wpa, domain;
3type wpa_exec, exec_type, file_type;
4
5init_daemon_domain(wpa)
Stephen Smalleyb1cb3202013-10-29 14:42:41 -04006allow wpa kernel:system module_request;
7allow wpa self:capability { setuid net_admin setgid net_raw };
8allow wpa cgroup:dir create_dir_perms;
9allow wpa self:netlink_route_socket *;
10allow wpa self:netlink_socket *;
11allow wpa self:packet_socket *;
12allow wpa self:udp_socket *;
13allow wpa wifi_data_file:dir create_dir_perms;
14allow wpa wifi_data_file:file create_file_perms;
15unix_socket_send(wpa, system_wpa, system_server)
16allow wpa random_device:chr_file r_file_perms;
17
18# Create a socket for receiving info from wpa
Stephen Smalley7ade68d2014-02-21 11:28:20 -050019type_transition wpa wifi_data_file:dir wpa_socket "sockets";
20allow wpa wpa_socket:dir create_dir_perms;
Stephen Smalleyb1cb3202013-10-29 14:42:41 -040021allow wpa wpa_socket:sock_file create_file_perms;
Nick Kralevichba1a7312014-01-24 15:46:27 -080022
23# Allow wpa_cli to work. wpa_cli creates a socket in
24# /data/misc/wifi/sockets which wpa supplicant communicates with.
25userdebug_or_eng(`
26 unix_socket_send(wpa, wpa, su)
27')