framework/security/libprivilege-control.git
10 years agoAdding Smack rule for obexd to allow to RX to all app's shared directory 2.2_release submit/tizen_2.2/20130716.173241 submit/tizen_2.2/20130717.015510 submit/tizen_2.2/20130717.053121
Bumjin Im [Tue, 16 Jul 2013 07:41:37 +0000 (16:41 +0900)]
Adding Smack rule for obexd to allow to RX to all app's shared directory

Change-Id: I2ac460b6e59577291f5188708b6b2c5f99500c8b

10 years agoAdding W rules to allow email-service move draft email to draft box
Bumjin Im [Sat, 13 Jul 2013 11:12:47 +0000 (20:12 +0900)]
Adding W rules to allow email-service move draft email to draft box

Change-Id: Icfa0c2b17c8ce248eb6bc3c9126922cb8eb1112d

10 years ago[Release] libprivilege-control_0.0.39.TIZEN submit/tizen_2.2/20130714.151203
Krzysztof Jackiewicz [Fri, 12 Jul 2013 20:04:38 +0000 (22:04 +0200)]
[Release] libprivilege-control_0.0.39.TIZEN

* Smack file concurrent write fixed

Change-Id: I6caf7671904a50f374c66c8e888b50d51c269860

10 years agoFile locking added
Krzysztof Jackiewicz [Fri, 12 Jul 2013 19:23:19 +0000 (21:23 +0200)]
File locking added

[Issue#] N/A
[Feature/Bug] N/A
[Problem] Two processes may write to smack file at the same time
[Cause] No proper file locking
[Solution] File locking added. Self rules for av and appsetting skipped

[Verification] Tests should pass. Run test_install.sh. Reported number of rules should not change.

Change-Id: I6dc20de7ae518889156a90d3d9c79714b37c2096

10 years agoWork around for rule loading to allow email-service and contacts-servce access to...
Bumjin Im [Fri, 12 Jul 2013 08:41:11 +0000 (17:41 +0900)]
Work around for rule loading to allow email-service and contacts-servce access to shared directory of everybody.

Change-Id: I272a8b29058a736131046e0b3be2a6103e0f62e0

10 years agoMerge rsa/tizen_2.2 into rsa/master
Krzysztof Jackiewicz [Tue, 9 Jul 2013 16:49:50 +0000 (18:49 +0200)]
Merge rsa/tizen_2.2 into rsa/master

Change-Id: I0db5006222b90dbd52420f6e10985f9918fbd11c

10 years ago[Release] libprivilege-control_0.0.38.TIZEN
Krzysztof Jackiewicz [Tue, 9 Jul 2013 16:49:02 +0000 (18:49 +0200)]
[Release] libprivilege-control_0.0.38.TIZEN

* Fixed segfault in set_app_privilege
* Prevent bugfixes

Change-Id: I96e4d1556eb684dc3827ef44c1a6decfe9d1a1c8

10 years agoFixing segfault in libprivilege-control
Zbigniew Jasinski [Tue, 9 Jul 2013 10:01:28 +0000 (12:01 +0200)]
Fixing segfault in libprivilege-control

[Issue#]        SSDWSSP-371
[Bug/Feature]   segfault in libprivilege-control
[Cause]         In set_app_privilege() one should be able to get smack context
                from path even if there's no SMACK on the device.
[Solution]      Added function params checking.
[Verification]  Running libprivilege-control-test.

Change-Id: Id9db1f59aa2c95eab8781747ef6a00bbc6400cc2

10 years agoFixing prevent defects in libprivilege-control:
Marcin Niesluchowski [Tue, 2 Jul 2013 11:55:11 +0000 (13:55 +0200)]
Fixing prevent defects in libprivilege-control:
* 63125; Minor; Unchecked return value; In function app_uninstall_remove_early_rules
  in src/privilege-control.c (defect changed to false positive)
* 63145; Critical; Dereference after null check; In function main
  in rule_loader/rule_loader.c
* 63146; Critical; Dereference after null check; In function
  app_uninstall_remove_early_rules in src/privilege-control.c

[Issue#]        N/A
[Bug/Feature]   There are 3 prevent issues to solve.
[Cause]         N/A
[Solution]      N/A
[Verification]  Running libprivilege tests. All should pass.

Change-Id: I5298a40ebef24286fec1149b48cac33e32753c00

10 years agoMerge rsa/tizen_2.2 into rsa/master
Krzysztof Jackiewicz [Tue, 9 Jul 2013 08:47:35 +0000 (10:47 +0200)]
Merge rsa/tizen_2.2 into rsa/master

Change-Id: I70b290feb641bd95f68a8ee93908c2b7ed90ac46

10 years ago[Release] libprivilege-control_0.0.37.TIZEN
Krzysztof Jackiewicz [Tue, 9 Jul 2013 08:46:56 +0000 (10:46 +0200)]
[Release] libprivilege-control_0.0.37.TIZEN

* Add contact-service and email-service rule to read shared dirs.

Change-Id: Ifcb064a53eda772a20df5fba52fda86ea62c3a9d

10 years agoMerge "Add contact-service and email-service rule to read shared dirs."
Tomasz Swierczek [Tue, 9 Jul 2013 08:43:25 +0000 (08:43 +0000)]
Merge "Add contact-service and email-service rule to read shared dirs."

10 years agoMerge remote-tracking branch 'rsa/tizen_2.2' into rsa/master
Krzysztof Jackiewicz [Tue, 9 Jul 2013 08:13:51 +0000 (10:13 +0200)]
Merge remote-tracking branch 'rsa/tizen_2.2' into rsa/master

Change-Id: Idce316ac3ccae3457d3b50b7403d5a685bf75fec

10 years agoAdd contact-service and email-service rule to read shared dirs.
Janusz Kozerski [Tue, 9 Jul 2013 08:13:32 +0000 (10:13 +0200)]
Add contact-service and email-service rule to read shared dirs.

[Issue#]        N/A
[Bug/Feature]   Add contact-service and email-service rule to read shared dirs.
[Cause]         N/A
[Solution]      N/A
[Verification]  Build, run tests, check if "contats-service ~SHARED_DIR~ rx" and
                "email-service ~SHARED_DIR~ rx" rules are pressent in system.

Change-Id: I0a54ac67a15e9dd5e6509eecd5bdffbc008379ce

10 years ago[Release] libprivilege-control_0.0.36.TIZEN
Krzysztof Jackiewicz [Mon, 8 Jul 2013 14:33:33 +0000 (16:33 +0200)]
[Release] libprivilege-control_0.0.36.TIZEN

* Boot-time rule loading optimization

Change-Id: Iee85854ff3f6fa68ec244e24b73e398749eb0763

10 years agoAdding script for early rules loading
Zofia Abramowska [Fri, 21 Jun 2013 09:38:32 +0000 (11:38 +0200)]
Adding script for early rules loading

[Issue#] SSDWSSP-216
[Feature] Adding script and binary for early rules loading (for
applications needed by livebox)
[Cause] Some applications need to be properly loaded with
livebox
[Solution] Added script and binary which loades rules from early
rules directory
[Verification] this commit depends on
http://slp-info.sec.samsung.net/gerrit/#/c/224189/
when it will be merged livebox should start properly on target

Change-Id: I6ae711d10d90a9f8537b7c514db9cbbaa7bb49db

10 years agoEarly rule loading - livebox issue.
Janusz Kozerski [Wed, 12 Jun 2013 10:40:52 +0000 (12:40 +0200)]
Early rule loading - livebox issue.

[Issue#]        SSDWSSP-298
[Bug/Feature]   Livebox issue fix.
[Cause]         Missing rules while showing homescreen.
[Solution]      Add early-rules loading.
[Verification]  Compile. Install at least 2 widgets,
                then check if /opt/etc/smack-app-early/accesses.d/WRT file contains
                a "livebox.web-provider ~APP~ rwx" rule for every app.
                Then uninstall one app and check if rule for this app is gone.
                Others rules should remain untouched.

Change-Id: Ie94713620038ebbdcab4e2d41fc01550a6a78fdb

10 years agoImplementation of background rule loading
Pawel Polawski [Mon, 3 Jun 2013 12:22:23 +0000 (14:22 +0200)]
Implementation of background rule loading

[Issue#]        SSDWSSP-298
[Bug/Feature]   Loading SMACK rules in background during device start
[Cause]         Loading rules during boot take to much time
[Solution]      Rukles loaded for all apps after boot
[Verification]  Compile. After homescreen shows up rules should load
                automaticly

Change-Id: Ie84aad8e35761a22d1197e994d3eb89ec31587d4

10 years agoexecute pkg_smack at first boot(temporary)
Kidong Kim [Fri, 5 Jul 2013 08:51:47 +0000 (17:51 +0900)]
execute pkg_smack at first boot(temporary)

10 years ago[Release] libprivilege-control_0.0.35.TIZEN
Tomasz Swierczek [Fri, 5 Jul 2013 08:07:58 +0000 (10:07 +0200)]
[Release] libprivilege-control_0.0.35.TIZEN

* Fix for setting dac

Change-Id: I9bf1bf4bb01cf284b7af163ca7e04375d3ccd5fd

10 years agoFixing segfault in get_app_gids when app_id = NULL
Zbigniew Jasinski [Fri, 5 Jul 2013 07:54:18 +0000 (09:54 +0200)]
Fixing segfault in get_app_gids when app_id = NULL

Change-Id: I1b9e182366da921f1a6bfee50a87e694ca3c1f7f

10 years ago[Release] libprivilege-control_0.0.34.TIZEN
Krzysztof Jackiewicz [Wed, 3 Jul 2013 17:24:23 +0000 (19:24 +0200)]
[Release] libprivilege-control_0.0.34.TIZEN

* SMACK configuration files moved to smack-privilege-config repo

Change-Id: I946b6fbb09d301abb889bb6b2576e581e5954097

10 years ago[Issue#] SSDWSSP-302
Zbigniew Jasinski [Wed, 3 Jul 2013 15:16:54 +0000 (17:16 +0200)]
[Issue#]        SSDWSSP-302
[Bug/Feature]   Keeping *.smack files in separate repository.
[Cause]         SMACK rule changes cause rebuilding many packages due to
                libprivilege-control dependencies.
[Solution]      Exclude SMACK rules files from libprivilege-control package.
[Verification]  Running tests.

Change-Id: I8513740df4afe3ceac4152fd032f8fad3eb1966a

10 years agoadd new smack rules for OSP se/secureelement privilege
Kidong Kim [Mon, 1 Jul 2013 10:30:57 +0000 (19:30 +0900)]
add new smack rules for OSP se/secureelement privilege

10 years agoadd smack rules for sdcard
Kidong Kim [Mon, 1 Jul 2013 09:26:06 +0000 (18:26 +0900)]
add smack rules for sdcard

10 years agoadd new smack rules for user-space access control
Kidong Kim [Sat, 29 Jun 2013 04:35:58 +0000 (13:35 +0900)]
add new smack rules for user-space access control

10 years ago[Release] libprivilege-control_0.0.33.TIZEN
Tomasz Swierczek [Thu, 27 Jun 2013 10:16:22 +0000 (12:16 +0200)]
[Release] libprivilege-control_0.0.33.TIZEN

* Fix bugs reported by prevent tool
* Reduced number of logs

Change-Id: If8fa471a8c9ef2240feb032744ad8e89828f5138

10 years agoadd smack rules for OSP/WEB app to access clipboard
Kidong Kim [Thu, 27 Jun 2013 07:01:21 +0000 (16:01 +0900)]
add smack rules for OSP/WEB app to access clipboard

10 years agoadd smack rules to synchronize with private
Kidong Kim [Thu, 27 Jun 2013 02:23:45 +0000 (11:23 +0900)]
add smack rules to synchronize with private

10 years agoadd smack rules
Kidong Kim [Tue, 25 Jun 2013 23:40:04 +0000 (08:40 +0900)]
add smack rules

10 years agoFixing prevent bugs on libprivilege-control:
Marcin Niesluchowski [Mon, 24 Jun 2013 12:27:57 +0000 (14:27 +0200)]
Fixing prevent bugs on libprivilege-control:
* 58766; Critical; Resource Leak; In function register_app_for_public_dirs
  in src/privilege-control.c
* 58764; Critical; Resource Leak; In function app_register_av_internal
  in src/privilege-control.c
* 53409; Critical; Resource Leak; In function register_app_for_av
  in src/privilege-control.c
* 51719; Critical; Resource Leak; In function get_app_gids
  in src/access-db.c
* 51572; Critical; Explicit null dereferenced; In function get_all_ids_internal
  in src/access-db.c
* 55418; Minor; Unchecked return value from library; In function mark_rules_as_loaded
  in src/privilege-control.c

[Issue#]        SSDWSSP-335
[Bug/Feature]   Recent prevent bugs need fix.
[Cause]         N/A
[Solution]      N/A
[Verification]  Running tests.

Change-Id: I381da2083d8a0fac1be930bfdbf3fca688710fc1

10 years agoadd new smack rule for WRT
Kidong Kim [Sun, 23 Jun 2013 23:28:47 +0000 (08:28 +0900)]
add new smack rule for WRT

10 years agoReducing error logs number.
Marcin Niesluchowski [Tue, 18 Jun 2013 13:50:38 +0000 (15:50 +0200)]
Reducing error logs number.

[Issue#]        SSDWSSP-331
[Bug/Feature]   Too many error logs.
[Cause]         N/A
[Solution]      N/A
[Verification]  Running tests.

Change-Id: I7a5516b0cd68d9217db2da9ba185d6cc9536b9dc

10 years ago[Release] libprivilege-control_0.0.32.TIZEN
Bartlomiej Grzelewski [Thu, 20 Jun 2013 09:16:19 +0000 (11:16 +0200)]
[Release] libprivilege-control_0.0.32.TIZEN

* Fix bugs reported by prevent tool.
* Sensitive information will be loged with SECURE_LOGE instead of C_LOGD.

Change-Id: If57c46e699868c644018a9488c8a85f4ddd217ca

10 years agoadd smack default rules
Kidong Kim [Thu, 20 Jun 2013 07:49:42 +0000 (16:49 +0900)]
add smack default rules

10 years agoFixing prevent critical defects in libprivilege-control and some log messages.
Marcin Niesluchowski [Thu, 13 Jun 2013 15:11:14 +0000 (17:11 +0200)]
Fixing prevent critical defects in libprivilege-control and some log messages.
Critical "Explicit null dereferenced" in function add_api_feture() in src/privilege-control.c fixed.
Critical "Explicit null dereferenced" in function get_all_ids_internal() in src/access-db.c
seems to be false warning.

[Issue#]        SSDWSSP-306
[Bug/Feature]   Fix prevent defects
[Cause]         Prevent server signalizes defects
[Solution]      N/A
[Verification]  Running tests and checking prevent output.

Change-Id: Ia0e407428629ddaa7da3df4a672e00cc0cd6bcf6

10 years agoLog messages refactoring
Zbigniew Jasinski [Mon, 17 Jun 2013 13:59:56 +0000 (15:59 +0200)]
Log messages refactoring

Also fixed segfault in message logging

[Issue#]        SSDWSSP-323
[Bug/Feature]   Log messages refactoring
[Cause]         Legal issues with prohibited words in logs (ie. password)
[Solution]      Use SECURE_LOG* macro
[Verification]  Compile with LOG_DEBUG_ENABLED and run. No tests should fail

Change-Id: I760846428d8708cce5a1beeb88fd2bfdcbaa1a57

10 years agoadd smack rules for WRT app
Kidong Kim [Wed, 19 Jun 2013 04:28:03 +0000 (13:28 +0900)]
add smack rules for WRT app

10 years agoMerge "Added SECURE_LOG* macro"
Bartlomiej Grzelewski [Tue, 18 Jun 2013 14:33:04 +0000 (14:33 +0000)]
Merge "Added SECURE_LOG* macro"

10 years agoAdded SECURE_LOG* macro
Zbigniew Jasinski [Tue, 18 Jun 2013 08:52:16 +0000 (10:52 +0200)]
Added SECURE_LOG* macro

[Issue#]        SSDWSSP-323
[Bug/Feature]   Log messages refactoring
[Cause]         SECURE_LOG* macro added for log messages refactoring
[Solution]      Added SECURE_LOG* macro
[Verification]  Compile with LOG_DEBUG_ENABLED and run. No tests should fail

Change-Id: Id2926d7a880f83c890f597aead7adc73b9e0dc72

10 years agoadd smack rules for WRT app
Kidong Kim [Tue, 18 Jun 2013 08:23:53 +0000 (17:23 +0900)]
add smack rules for WRT app

10 years agoadd smack rule of OSP apps for e17
Kidong Kim [Mon, 17 Jun 2013 14:23:30 +0000 (23:23 +0900)]
add smack rule of OSP apps for e17

10 years ago[Release] libprivilege-control_0.0.31.TIZEN
Krzysztof Jackiewicz [Mon, 17 Jun 2013 13:13:39 +0000 (15:13 +0200)]
[Release] libprivilege-control_0.0.31.TIZEN

* Another release because previous one was not triggered

Change-Id: Ibc371f520e73c9a49e0f8a35906ae222bb54d59c

10 years ago[Release] libprivilege-control_0.0.30.TIZEN
Krzysztof Jackiewicz [Mon, 17 Jun 2013 12:44:16 +0000 (14:44 +0200)]
[Release] libprivilege-control_0.0.30.TIZEN

* Remaining smack_accesses_add replaced with smack_accesses_add_modify

Change-Id: I57e3bcc96adc4928d23a990b893e074a1a5d35cc

10 years agoAdded missing part of fix for rule overwriting issue
Tomasz Swierczek [Fri, 31 May 2013 16:03:16 +0000 (18:03 +0200)]
Added missing part of fix for rule overwriting issue

[Issue#]       N/A
[Bug]          Some rules in apps rule file were overwriting rules
[Cause]        smack_accesses_add used instead of smack_accesses_add_modify. Not all required changes from
86da6484f2e4cad76565b8ddac0d126e3b5327fb have been applied on rsa.
[Solution]     changed function
[Verification] Install FtApp and see if rules for aospd* label are rx or rwx (should be latter)

Change-Id: Ic863b013b069e9a97d3b04e79c84f5c1a54f1f2a

10 years agoadd new rules for OSP app
Kidong Kim [Mon, 17 Jun 2013 06:42:44 +0000 (15:42 +0900)]
add new rules for OSP app

10 years agoadd smack rules
Kidong Kim [Mon, 17 Jun 2013 02:55:25 +0000 (11:55 +0900)]
add smack rules

10 years agofix rules and labeling on db
Kidong Kim [Thu, 13 Jun 2013 02:26:32 +0000 (11:26 +0900)]
fix rules and labeling on db

10 years agoadd smack rules for app-package::db
Kidong Kim [Wed, 12 Jun 2013 06:43:52 +0000 (15:43 +0900)]
add smack rules for app-package::db

10 years agoMerge rsa/tizen_2.2 into rsa/master
Krzysztof Jackiewicz [Mon, 10 Jun 2013 15:05:57 +0000 (17:05 +0200)]
Merge rsa/tizen_2.2 into rsa/master

Change-Id: Ia2e52cf82801cc5bae0575bf53991d0340a5054f

10 years ago[Release] libprivilege-control_0.0.29.TIZEN
Krzysztof Jackiewicz [Mon, 10 Jun 2013 15:01:25 +0000 (17:01 +0200)]
[Release] libprivilege-control_0.0.29.TIZEN

* Fixed creation of rule sets with missing ----- (change-rule interface)
* New app_type_t values (partner and platform)
* Add error logs in app_give_access.
* Add implementation for appsetting privilege
* Change parameter names app_id to pkg_id in API functions
* Comment to app_revoke_permissions() changed.
* Fast boot optimization
* Add value APP_PATH_ANY_LABEL to enum app_path_type_t.
* Fixing Rule Loading fail for livebox apps on next reboot

Change-Id: Iff3099b508c2927f6c8c4eddcf55fa730a08d0c1

10 years agoFixing Rule Loading fail for livebox apps on next reboot
Bumjin Im [Sat, 8 Jun 2013 08:49:19 +0000 (17:49 +0900)]
Fixing Rule Loading fail for livebox apps on next reboot

[Issue#] N/A
[Bug] N/A
[Cause] N/A
[Solution] Fixing Rule Loading fail for livebox apps on next reboot

Change-Id: Ia99c5d3bbb0c207a226fe7c70c1bc7652f431746

10 years agosynchronize OSP/WRT rules with private repository
Kidong Kim [Mon, 10 Jun 2013 11:49:19 +0000 (20:49 +0900)]
synchronize OSP/WRT rules with private repository

10 years agosynchronize OSP/WRT rules with private repository
Kidong Kim [Mon, 10 Jun 2013 02:26:46 +0000 (11:26 +0900)]
synchronize OSP/WRT rules with private repository

10 years agoAdd value APP_PATH_ANY_LABEL to enum app_path_type_t.
Bartlomiej Grzelewski [Wed, 29 May 2013 15:16:33 +0000 (17:16 +0200)]
Add value APP_PATH_ANY_LABEL to enum app_path_type_t.

[Issue#]   SSDWSSP-307
[Bug]      N/A
[Cause]    Some directories must be set up by installer manually.
[Solution] N/A

[Verification] Run libprivilege-control tests.

Change-Id: Iff482d43b6f5e08603a0c74820b713f8e8def5c9

10 years agoFast boot optimization
Janusz Kozerski [Mon, 27 May 2013 08:22:56 +0000 (10:22 +0200)]
Fast boot optimization

[Issue#]       SSDWSSP-295
[Feature]      Rules for each app are now loaded while first run of the application.
[Cause]        N/A
[Solution]     N/A

[Verification] Build, install, reboot target. Run libprivilege-control tests.

Change-Id: I11b2c1738a4cfb7770fc680dbc02c88435e995f7

10 years agoComment to app_revoke_permissions() changed.
Marcin Niesluchowski [Wed, 22 May 2013 13:37:38 +0000 (15:37 +0200)]
Comment to app_revoke_permissions() changed.

[Issue#]        SSDWSSP-260
[Bug/Feature]   Comment to app_revoke_permissions() was not consistent with actual function requirements.
[Cause]         N/A
[Solution]      N/A
[Verification]  N/A

Change-Id: I639247fa2af81d4adb1a153d193e94f48b1edc83

10 years agoChange parameter names app_id to pkg_id in API functions
Jan Cybulski [Fri, 24 May 2013 08:57:39 +0000 (10:57 +0200)]
Change parameter names app_id to pkg_id in API functions

        [Issue#]        SSDWSSP-290
        [Bug/Feature]   N/A
        [Cause]         N/A
        [Solution]      N/A
        [Verification]  Build, run libprivilege tests.

Change-Id: I27a44c9c7a1491b0ff2c3827d76bf1eea4b2e2f2

10 years agoAdd implementation for appsetting privilege
Jan Cybulski [Thu, 23 May 2013 10:12:28 +0000 (12:12 +0200)]
Add implementation for appsetting privilege

    [Issue#]        SSDWSSP-241
    [Bug/Feature]   Implement an unique feature for an appsetting privilege.
                    The privilege should give RWX access to all registered
                    setting folders and RX access to all applications.
    [Cause]         N/A
    [Solution]      Change in app_add_permissions_internal.
    [Verification]  Run libprivilege tests.
                    Test privilege_control16_appsettings_privilege should pass

Change-Id: Icdb2b6dc44395ec7a723064bc2db56ef634e609d

10 years agoAdd error logs in app_give_access.
Bartlomiej Grzelewski [Thu, 9 May 2013 14:43:05 +0000 (16:43 +0200)]
Add error logs in app_give_access.

[Issue#]   SSDWSSP-226
[Bug]      N/A
[Cause]    N/A
[Solution] N/A

[Verification] Successful compilation. Run test.

Change-Id: I7bb100c39a6fb139414a88e72a73c60282f4168f

10 years agoprivilege-control.c and privilege-control.h extended by new app_type_t values. New...
Marcin Niesluchowski [Mon, 20 May 2013 09:56:27 +0000 (11:56 +0200)]
privilege-control.c and privilege-control.h extended by new app_type_t values. New WRT_partner.smack, WRT_platform.smack, OSP_partner.smack and OSP_platform.smack created from WRT.smack and OSP.smack.

[Issue#]        SSDWSSP-270
[Bug/Feature]   Change app_enable_permissions() input app type - extend to new app types.
[Cause]         N/A
[Solution]      N/A
[Verification]  Creating and running tests for new app types.

Change-Id: I4c5525d2dfc9c626b07a8dae33f073db7460ce9c

10 years agoFixed creation of rule sets with missing ----- (change-rule interface)
Tomasz Swierczek [Fri, 31 May 2013 16:03:16 +0000 (18:03 +0200)]
Fixed creation of rule sets with missing ----- (change-rule interface)

[Issue#]       N/A
[Bug]          Some rules in apps rule file were overwriting rules
[Cause]        smack_accesses_add used instead of smack_accesses_add_modify
[Solution]     changed function
[Verification] Install FtApp and see if rules for aospd* label are rx or rwx (should be latter)

Change-Id: I66e2cae21865bd4be1b885df8d958a5fa0409d52

Conflicts:

src/privilege-control.c

10 years ago[Release] libprivilege-control_0.0.28.TIZEN
Krzysztof Jackiewicz [Wed, 29 May 2013 16:17:07 +0000 (18:17 +0200)]
[Release] libprivilege-control_0.0.28.TIZEN

* smack_pid_have_access and get_smack_label_from_process added.
* special handling for http://tizen.org/privilege/antivirus
* New API for labeling directories and files
* Changing way of mapping feature to file name
* refactoring

Change-Id: I0eb10d8dd99178c226cb678263d2026e459f7fb1

10 years agoChanging way of mapping feature to file name
Zofia Abramowska [Wed, 29 May 2013 15:50:23 +0000 (17:50 +0200)]
Changing way of mapping feature to file name

[Issue#] SSDWSSP-292
[Feature] Supporting wider variety of feature names
[Cause] Previously there was no difference in mapping features
named like http://<something>/feature.name, no matter what
<something> was. This isn't proper anymore.
[Solution] Mapping whole feature name to file name
[Verification] Build. Run tests. Test for adding api features will fail.

Change-Id: I4c459e845215c7dcab522a415a560e86936b057a

10 years agoNew API for labeling directories and files.
Rafal Krypa [Thu, 23 May 2013 09:54:34 +0000 (11:54 +0200)]
New API for labeling directories and files.

[Issue#]       SSDWSSP-240
[Feature]      New API for labeling directories and files
[Cause]        Redesigned with new requested feature implementation
[Solution]     Provide new function app_setup_path(), deprecate app_label_dir(), app_label_shared_dir() and app_add_shared_dir_readers()
[Verification] Build, install, reboot target. Run libprivilege-control tests.

Change-Id: I9e8ad0c279fc8edfe2ef3764382d6726f5615dcc

10 years agoCode refactoring, new internal function for adding single rule for an application.
Rafal Krypa [Wed, 22 May 2013 13:13:57 +0000 (15:13 +0200)]
Code refactoring, new internal function for adding single rule for an application.

[Issue#]       N/A
[Feature]      New static function app_add_rule()
[Cause]        The same functionality implemented in several places.
[Solution]     Refactoring for better code reuse.
[Verification] Build, install, reboot target. Run libprivilege-control tests.

Change-Id: Id76ae8a435e38092c219ed40b65b11b0f4690b42

10 years agoImplement special handling for http://tizen.org/privilege/antivirus
Janusz Kozerski [Mon, 13 May 2013 15:27:53 +0000 (17:27 +0200)]
Implement special handling for tizen.org/privilege/antivirus

[Issue#]        SSDWSSP-239
[Bug/Feature]   Implement special handling for http://tizen.org/privilege/antivirus
[Cause]         app_register_av() is deprecated.
[Solution]      N/A
[Verification]  Build, install. Install apps.installer.rpm from task (in CAM), and try to install McAfee anti virus (in CAM).

Change-Id: Icd2ba4f8385dedc53fe1e380bef1463e228bcc2e

10 years agoMerge remote-tracking branch 'rsa/tizen_2.1' into rsa_master
Krzysztof Jackiewicz [Wed, 29 May 2013 15:20:21 +0000 (17:20 +0200)]
Merge remote-tracking branch 'rsa/tizen_2.1' into rsa_master

10 years agoAdd API functions smack_pid_have_access and get_smack_label_from_process.
Janusz Kozerski [Mon, 6 May 2013 12:34:13 +0000 (14:34 +0200)]
Add API functions smack_pid_have_access and get_smack_label_from_process.

[Issue#]   SSDWSSP-220
[Feature]  Add new function: smack_pid_have_access. This function calls smack_have_access, and if there's no access granted then check if process have CAP_MAC_OVERRIDE.
[Problem]  N/A
[Cause]    N/A
[Solution] N/A

[Verification] Build, install.

Change-Id: If319fd7b176d9a7e1ecb38458f6178e5e7f9865c

10 years ago[Release] libprivilege-control_0.0.27.TIZEN
Krzysztof Jackiewicz [Wed, 29 May 2013 14:12:06 +0000 (16:12 +0200)]
[Release] libprivilege-control_0.0.27.TIZEN

* Executable link labeling. API deprecation.

Change-Id: Ie9669c42b31aa066fc9955c80c282bcb41f9d04d

10 years agoRevert "Fixing app_revoke_internal() used by app_revoke_permissions()"
Marcin Niesluchowski [Wed, 22 May 2013 12:12:47 +0000 (21:12 +0900)]
Revert "Fixing app_revoke_internal() used by app_revoke_permissions()"

This reverts commit 8b61c02bade31201966fdeb822569b2b5c2da5b3

11 years agoadd new smack rule
Kidong Kim [Tue, 28 May 2013 07:42:29 +0000 (16:42 +0900)]
add new smack rule

11 years agoWRT binary link handling updated.
Krzysztof Jackiewicz [Tue, 7 May 2013 06:37:36 +0000 (08:37 +0200)]
WRT binary link handling updated.

[Issue#] N/A
[Feature/Bug] N/A
[Problem] WRT application label should be retrieved from link to executable
xattrs. Currently widget_id is the label.
[Cause] N/A
[Solution] Smack label is retrieved from link to executable. app_label_dir
has been modified to label links to executable files with proper exec label.

[Verification] Run libprivilege-control-test. Reboot, install a widget and
launch it. http://slp-info.sec.samsung.net/gerrit/#/c/204855/

Change-Id: Iae87854283989f0d3ff0b76c9092c10654f47c7c

11 years agoFixing app_revoke_internal() used by app_revoke_permissions()
Marcin Niesluchowski [Tue, 14 May 2013 15:36:18 +0000 (17:36 +0200)]
Fixing app_revoke_internal() used by app_revoke_permissions()

[Issue#]        SSDWSSP-260
[Bug/Feature]   Libprivilege-control tests fail
[Cause]         N/A
[Solution]      N/A
[Verification]  Running tests

Change-Id: I72f654279998f4622ce2a9564580242b29ec9d80

11 years agoMarking app_give_access & app_revoke_access as deprecated
Zofia Abramowska [Mon, 13 May 2013 14:10:19 +0000 (16:10 +0200)]
Marking app_give_access & app_revoke_access as deprecated

[Issue#] SSDWSSP-229
[Bug/Feature] N/A
[Cause] Reimplementing process_app_give_access in security-server
[Solution] N/A
[Verification] Successful build

Change-Id: Id81146bc2892353ec2f55976a4d77077d2744e43

11 years agoadd rule for wrt_launchpad_daemon
Kidong Kim [Tue, 21 May 2013 08:48:34 +0000 (17:48 +0900)]
add rule for wrt_launchpad_daemon

11 years agoAdjusting Rules for boolmark tizen_2.1 accepted/tizen_2.1/20130520.093051 submit/tizen_2.1/20130516.045506
Bumjin Im [Wed, 15 May 2013 10:30:10 +0000 (19:30 +0900)]
Adjusting Rules for boolmark

11 years agoadd smack rules for sdcard
Kidong Kim [Wed, 15 May 2013 07:26:57 +0000 (16:26 +0900)]
add smack rules for sdcard

11 years agoadd smack rules for osp/web app submit/tizen_2.1/20130515.030959
Kidong Kim [Tue, 14 May 2013 08:58:30 +0000 (17:58 +0900)]
add smack rules for osp/web app

11 years agoMerge "Update .smack files 2" into tizen_2.1
Bumjin Im [Tue, 14 May 2013 06:03:52 +0000 (15:03 +0900)]
Merge "Update .smack files 2" into tizen_2.1

11 years agoUpdate .smack files 2
jinha.hwang [Tue, 14 May 2013 05:54:44 +0000 (14:54 +0900)]
Update .smack files 2

11 years agoadd new rules for system::share
Kidong Kim [Tue, 14 May 2013 05:08:26 +0000 (14:08 +0900)]
add new rules for system::share

11 years ago[Release] libprivilege-control_0.0.26.TIZEN
Krzysztof Jackiewicz [Mon, 13 May 2013 17:06:30 +0000 (19:06 +0200)]
[Release] libprivilege-control_0.0.26.TIZEN

* Added rules for OSP/WRT apps for app_give_access API usage in security-server

Change-Id: Ia529d15219f89d53f27c504b9715207acf1f8ab0

11 years agoAdded rules for OSP/WRT apps for app_give_access API usage in security-server
Tomasz Swierczek [Mon, 13 May 2013 16:25:07 +0000 (18:25 +0200)]
Added rules for OSP/WRT apps for app_give_access API usage in security-server

[Issue#]        TDIS-5744
[Bug/Feature]   Missing SMACK rules for runtime check for access to API.
[Cause]         N/A
[Solution]      Added rules - temporarily to OSP.smack and WRT.smack
[Verification]  use app_enable_permissions() - rule file should contain rule for security-server::api-data-share

Change-Id: Iefc140b1a93e5eec5507e466ea2db11641cff222

11 years agoAdded rules for OSP/WRT apps for app_give_access API usage in security-server
Tomasz Swierczek [Mon, 13 May 2013 16:25:07 +0000 (18:25 +0200)]
Added rules for OSP/WRT apps for app_give_access API usage in security-server

[Issue#]        TDIS-5744
[Bug/Feature]   Missing SMACK rules for runtime check for access to API.
[Cause]         N/A
[Solution]      Added rules - temporarily to OSP.smack and WRT.smack
[Verification]  use app_enable_permissions() - rule file should contain rule for security-server::api-data-share

Change-Id: I63fbe3dadbc147aef663c9bd0b6a5cdfd390702e

11 years agoadd new label and rules - system::share submit/tizen_2.1/20130514.053038
Kidong Kim [Mon, 13 May 2013 14:25:55 +0000 (23:25 +0900)]
add new label and rules - system::share

11 years agoAdding x rules for osp-*-services
Bumjin Im [Mon, 13 May 2013 06:55:05 +0000 (15:55 +0900)]
Adding x rules for osp-*-services

11 years agoAdjusting overwrapped Rule
Bumjin Im [Mon, 13 May 2013 00:57:31 +0000 (09:57 +0900)]
Adjusting overwrapped Rule

11 years agoRemoving Label for so files
Bumjin Im [Sun, 12 May 2013 07:39:57 +0000 (16:39 +0900)]
Removing Label for so files

11 years agoModifying Smack rules for Apps
Bumjin Im [Sun, 12 May 2013 05:18:30 +0000 (14:18 +0900)]
Modifying Smack rules for Apps

11 years agoModifying Smack rules for Apps
Bumjin Im [Sun, 12 May 2013 04:22:29 +0000 (13:22 +0900)]
Modifying Smack rules for Apps

11 years agoModifying Smack rules for Apps
Bumjin Im [Sun, 12 May 2013 03:58:22 +0000 (12:58 +0900)]
Modifying Smack rules for Apps

11 years agoModifying Smack rules for Apps
Bumjin Im [Sun, 12 May 2013 03:52:58 +0000 (12:52 +0900)]
Modifying Smack rules for Apps

11 years agoUpdate .smack files
jinha.hwang [Sat, 11 May 2013 14:24:20 +0000 (23:24 +0900)]
Update .smack files

11 years agoadd default rules
Kidong Kim [Sat, 11 May 2013 10:59:46 +0000 (19:59 +0900)]
add default rules

11 years agomerge back from tizen_2.1_smack
Kidong Kim [Fri, 10 May 2013 08:48:16 +0000 (17:48 +0900)]
merge back from tizen_2.1_smack

11 years agoRevert "Bug in app_install() fixed"
Tomasz Swierczek [Wed, 8 May 2013 07:35:50 +0000 (09:35 +0200)]
Revert "Bug in app_install() fixed"

This reverts commit 618655f8840efd978b073ce9239a16e1d061d14b.

11 years agoMerge "Merge remote-tracking branch 'tizendev/tizen_2.1_smack' into tizendev"
Krzysztof Jackiewicz [Tue, 7 May 2013 09:28:18 +0000 (18:28 +0900)]
Merge "Merge remote-tracking branch 'tizendev/tizen_2.1_smack' into tizendev"

11 years agoClean up libprivilege-control code
Krzysztof Jackiewicz [Mon, 6 May 2013 08:13:50 +0000 (10:13 +0200)]
Clean up libprivilege-control code

[Issue#] SSDWSSP-207
[Feature/Bug] N/A
[Problem] Cleanup the code
[Cause] N/A
[Solution] Unnecessary code removed. Comments updated

[Verification] Successfull compilation

Change-Id: I0bfe450301aee4b6f4f1b94336fef75d5c38dd60

11 years agoBug in app_install() fixed
Marcin Niesluchowski [Thu, 2 May 2013 12:18:32 +0000 (14:18 +0200)]
Bug in app_install() fixed

[Issue#]        SSDWSSP-223
[Bug/Feature]   Fix bugs that make libprivilege-control test fail
[Cause]         N/A
[Solution]      N/A
[Verification]  N/A

Change-Id: I88712168c64c8d35e7700124ff9da4ffefa32493