tree 0d233cc8cc8b7310d65132fda1c603e9ac2a0f28
parent 56b6eb406235c05398bb9c440593b0d0c2665c57
author Prashant Malani <pmalani@chromium.org> 1609192032 -0800
committer Commit Bot <commit-bot@chromium.org> 1609334141 +0000

debugd: Restrict EC Type C commands to typecd

The EcTypeCTool commands are meant for use by typecd exclusively. Add
D-Bus policy configuration to enforce this.

BUG=b:171725237
TEST=- Run debugd unit tests and ensure they pass.
     - Call the D-Bus command using dbus-send from command line. Verify
       that:
       * Called by itself, the command fails.
       * Called by using '/sbin/minijail0 -u typecd -g typecd', the
       command succeeds and the mode is entered. The command is
       dbus-send --system --dest=org.chromium.debugd
       --print-reply /org/chromium/debugd
       org.chromium.debugd.EcTypeCEnterMode uint32:1 uint32:1
       (Tested on a volteer with a Thunderbolt dock connected on port
       1).

Cq-Depend: chromium:2601785
Change-Id: I536ab4222e373d90e584aa6a7ed2a668c55f0b3d
Reviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/2605624
Commit-Queue: Prashant Malani <pmalani@chromium.org>
Reviewed-by: Mike Frysinger <vapier@chromium.org>
Reviewed-by: Jorge Lucangeli Obes <jorgelo@chromium.org>
Tested-by: Prashant Malani <pmalani@chromium.org>
