1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153
|
<!DOCTYPE busconfig PUBLIC "-//freedesktop//DTD D-BUS Bus Configuration 1.0//EN"
"http://www.freedesktop.org/standards/dbus/1.0/busconfig.dtd">
<!--
Copyright 2018 The Chromium Authors
Use of this source code is governed by a BSD-style license that can be
found in the LICENSE file.
-->
<busconfig>
<!-- vmc runs as chronos -->
<policy user="chronos">
<allow own="org.chromium.ChromeFeaturesService"/>
</policy>
<!-- upstart and tast run as root -->
<policy user="root">
<allow send_destination="org.chromium.ChromeFeaturesService"
send_interface="org.chromium.ChromeFeaturesServiceInterface"/>
</policy>
<!-- limit session_manager daemon visibility to only IsFeatureEnabled. -->
<policy user="session_manager">
<allow send_destination="org.chromium.ChromeFeaturesService"
send_interface="org.chromium.ChromeFeaturesServiceInterface"
send_member="IsFeatureEnabled"/>
</policy>
<!-- limit typecd daemon visibility to only IsPeripheralDataAccessEnabled -->
<policy user="typecd">
<allow send_destination="org.chromium.ChromeFeaturesService"
send_interface="org.chromium.ChromeFeaturesServiceInterface"
send_member="IsPeripheralDataAccessEnabled"/>
</policy>
<!-- limit dns-proxy daemon visibility to only IsDNSProxyEnabled -->
<policy user="dns-proxy">
<allow send_destination="org.chromium.ChromeFeaturesService"
send_interface="org.chromium.ChromeFeaturesServiceInterface"
send_member="IsDNSProxyEnabled"/>
<allow send_destination="org.chromium.ChromeFeaturesService"
send_interface="org.chromium.ChromeFeaturesServiceInterface"
send_member="IsRootNsDnsProxyEnabled"/>
</policy>
<!-- limit vm_concierge visibility to only IsFeatureEnabled and
GetFeatureParams -->
<policy user="crosvm">
<allow send_destination="org.chromium.ChromeFeaturesService"
send_interface="org.chromium.ChromeFeaturesServiceInterface"
send_member="IsFeatureEnabled"/>
<allow send_destination="org.chromium.ChromeFeaturesService"
send_interface="org.chromium.ChromeFeaturesServiceInterface"
send_member="GetFeatureParams"/>
</policy>
<policy user="resourced">
<allow send_destination="org.chromium.ChromeFeaturesService"
send_interface="org.chromium.ChromeFeaturesServiceInterface"
send_member="IsFeatureEnabled"/>
<allow send_destination="org.chromium.ChromeFeaturesService"
send_interface="org.chromium.ChromeFeaturesServiceInterface"
send_member="GetFeatureParams"/>
</policy>
<!-- limit cras visibility to only IsFeatureEnabled and
GetFeatureParams -->
<policy user="cras">
<allow send_destination="org.chromium.ChromeFeaturesService"
send_interface="org.chromium.ChromeFeaturesServiceInterface"
send_member="IsFeatureEnabled"/>
<allow send_destination="org.chromium.ChromeFeaturesService"
send_interface="org.chromium.ChromeFeaturesServiceInterface"
send_member="GetFeatureParams"/>
</policy>
<!-- limit dlp visibility to only IsFeatureEnabled -->
<policy user="dlp">
<allow send_destination="org.chromium.ChromeFeaturesService"
send_interface="org.chromium.ChromeFeaturesServiceInterface"
send_member="IsFeatureEnabled"/>
</policy>
<!-- limit secagentd visibility to only IsFeatureEnabled and
GetFeatureParams -->
<policy user="secagentd">
<allow send_destination="org.chromium.ChromeFeaturesService"
send_interface="org.chromium.ChromeFeaturesServiceInterface"
send_member="IsFeatureEnabled"/>
<allow send_destination="org.chromium.ChromeFeaturesService"
send_interface="org.chromium.ChromeFeaturesServiceInterface"
send_member="GetFeatureParams"/>
</policy>
<!-- limit missived visibility to only IsFeatureEnabled and
GetFeatureParams -->
<policy user="missived">
<allow send_destination="org.chromium.ChromeFeaturesService"
send_interface="org.chromium.ChromeFeaturesServiceInterface"
send_member="IsFeatureEnabled"/>
<allow send_destination="org.chromium.ChromeFeaturesService"
send_interface="org.chromium.ChromeFeaturesServiceInterface"
send_member="GetFeatureParams"/>
</policy>
<!-- limit power visibility to only IsFeatureEnabled -->
<policy user="power">
<allow send_destination="org.chromium.ChromeFeaturesService"
send_interface="org.chromium.ChromeFeaturesServiceInterface"
send_member="IsFeatureEnabled"/>
</policy>
<!-- limit devbroker visibility to only IsFeatureEnabled -->
<policy user="devbroker">
<allow send_destination="org.chromium.ChromeFeaturesService"
send_interface="org.chromium.ChromeFeaturesServiceInterface"
send_member="IsFeatureEnabled"/>
</policy>
<!-- limit iomanager visibility to only IsFeatureEnabled -->
<policy user="iomanager">
<allow send_destination="org.chromium.ChromeFeaturesService"
send_interface="org.chromium.ChromeFeaturesServiceInterface"
send_member="IsFeatureEnabled"/>
</policy>
<!-- limit fbpreprocessor visibility to only IsFeatureEnabled -->
<policy user="fbpreprocessor">
<allow send_destination="org.chromium.ChromeFeaturesService"
send_interface="org.chromium.ChromeFeaturesServiceInterface"
send_member="IsFeatureEnabled"/>
</policy>
<!-- limit oobe_config_save visibility to only IsFeatureEnabled. -->
<policy user="oobe_config_save">
<allow send_destination="org.chromium.ChromeFeaturesService"
send_interface="org.chromium.ChromeFeaturesServiceInterface"
send_member="IsFeatureEnabled"/>
</policy>
<!-- limit arc-camera visibility to only IsFeatureEnabled. -->
<policy user="arc-camera">
<allow send_destination="org.chromium.ChromeFeaturesService"
send_interface="org.chromium.ChromeFeaturesServiceInterface"
send_member="IsFeatureEnabled"/>
</policy>
<!-- limit regmond visibility to only IsFeatureEnabled. -->
<policy user="regmond">
<allow send_destination="org.chromium.ChromeFeaturesService"
send_interface="org.chromium.ChromeFeaturesServiceInterface"
send_member="IsFeatureEnabled"/>
</policy>
</busconfig>
|