Further changes needed to fix TIVI-2937 69/18769/2 accepted/tizen_generic accepted/tizen_ivi accepted/tizen_ivi_panda accepted/tizen/generic/20140402.145943 accepted/tizen/ivi/20140401.174335 accepted/tizen/ivi/panda/20140331.232001 accepted/tizen/ivi/release/20140331.231902 submit/tizen/20140331.232212 submit/tizen_ivi_release/20140331.232156
authorbrianjjones <brian.j.jones@intel.com>
Mon, 31 Mar 2014 22:10:30 +0000 (15:10 -0700)
committerbrianjjones <brian.j.jones@intel.com>
Mon, 31 Mar 2014 22:14:04 +0000 (15:14 -0700)
Change-Id: I8e01d0bcbe375372f5cdcbdcfced34ef9db07d61
Signed-off-by: brianjjones <brian.j.jones@intel.com>
ace/configuration/TizenPolicy.xml
packaging/wrt-security.changes

index ffaa9f8..dd02e58 100644 (file)
             </condition>
         </rule>
 
+        <!-- access to package -->
+        <rule effect="permit">
+            <condition combine="or">
+                <resource-match attr="device-cap" func="equal" match="packagemanager.install" />
+                <resource-match attr="device-cap" func="equal" match="package.info" />
+            </condition>
+        </rule>
+
         <!-- access to bluetooth -->
         <rule effect="permit">
             <condition combine="or">
                 <resource-match attr="device-cap" func="equal" match="contentmanager.write" />
             </condition>
         </rule>
-        
+
         <!-- access to external network -->
         <!-- XMLHttpRequestTizen and externalNetworkAccessTizen defined for Tizen Webapp -->
         <!-- Function of two capabilities are same to XMLHttpRequest and externalNetworkAccess of WAC -->
                 <environment-match attr="roaming" match="true" />
             </condition>
         </rule>
-        --> 
+        -->
 
         <rule effect="deny" />
 
                 <resource-match attr="device-cap" func="equal" match="contentmanager.write" />
             </condition>
         </rule>
-        
+
         <!-- access to external network -->
         <!-- XMLHttpRequestTizen and externalNetworkAccessTizen defined for Tizen Webapp -->
         <!-- Function of two capabilities are same to XMLHttpRequest and externalNetworkAccess of WAC -->
             </condition>
         </rule>
         -->
-        
+
         <rule effect="deny" />
 
     </policy>
                     sha-1 5A:C1:18:AC:6E:C7:EA:27:59:7D:5F:5A:1D:19:85:3D:A2:95:D5:18
                 </subject-match>
             </subject>
-        </target> 
+        </target>
 
         <rule effect="permit">
             <condition combine="or">
                 <resource-match attr="device-cap" func="equal" match="contentmanager.write" />
             </condition>
         </rule>
-        
+
         <!-- access to external network -->
         <!-- XMLHttpRequestTizen and externalNetworkAccessTizen defined for Tizen Webapp -->
         <!-- Function of two capabilities are same to XMLHttpRequest and externalNetworkAccess of WAC -->
             </condition>
         </rule>
         -->
-        
+
         <rule effect="deny" />
 
     </policy>
     <policy id="Tizen-Policy-Untrusted" description="Tizen's policy for untrusted domain" combine="permit-overrides">
         <!-- Specific Untrusted Policy for Tizen -->
 
+        <rule effect="permit">
+            <condition combine="or">
+                <resource-match attr="device-cap" func="equal" match="tizen" />
+            </condition>
+        </rule>
+
+        <rule effect="permit">
+            <condition combine="or">
+                <resource-match attr="device-cap" func="equal" match="speech" />
+            </condition>
+        </rule>
+
+        <!-- access to application -->
+        <rule effect="permit">
+            <condition combine="or">
+                <resource-match attr="device-cap" func="equal" match="application.launch" />
+                <resource-match attr="device-cap" func="equal" match="application.info" />
+            </condition>
+        </rule>
+
+        <!-- access to package -->
+        <rule effect="permit">
+            <condition combine="or">
+                <resource-match attr="device-cap" func="equal" match="packagemanager.install" />
+                <resource-match attr="device-cap" func="equal" match="package.info" />
+            </condition>
+        </rule>
+
+        <!-- access to bluetooth -->
+        <rule effect="permit">
+            <condition combine="or">
+                <resource-match attr="device-cap" func="equal" match="bluetooth.admin" />
+                <resource-match attr="device-cap" func="equal" match="bluetooth.gap" />
+                <resource-match attr="device-cap" func="equal" match="bluetooth.spp" />
+                <resource-match attr="device-cap" func="equal" match="bluetooth.health" />
+            </condition>
+        </rule>
+
+        <!-- access to content -->
+        <rule effect="permit">
+            <condition combine="or">
+                <resource-match attr="device-cap" func="equal" match="content.read" />
+                <resource-match attr="device-cap" func="equal" match="content.write" />
+            </condition>
+        </rule>
+
+        <!-- access to download feature -->
+
+       <rule effect="permit">
+            <condition combine="or">
+                <resource-match attr="device-cap" func="equal" match="download" />
+            </condition>
+        </rule>
+
+        <rule effect="permit">
+            <condition combine="or">
+                <resource-match attr="device-cap" func="equal" match="filesystem.read" />
+                <resource-match attr="device-cap" func="equal" match="filesystem.write" />
+            </condition>
+        </rule>
 
         <rule effect="deny" />
     </policy>
index 51c54fe..7af167c 100644 (file)
@@ -1,3 +1,6 @@
+* Mon Mar 31 2014 brianjjones <brian.j.jones@intel.com> accepted/tizen/ivi/20140328.205938@8643daf
+- Further changes needed to fix TIVI-2937
+
 * Wed Oct 23 2013 Hyunwoo Kim <hwlove.kim@samsung.com> 
 - Delete corresponding application data (AceAcceptedFeature, AceRequestedDevCaps) in ace DB when the application is deleted.