summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorBoon Jun Soh <boonjun@google.com>2023-12-08 18:54:45 +0800
committerTreehugger Robot <android-test-infra-autosubmit@system.gserviceaccount.com>2023-12-11 07:30:24 +0000
commita4fa4427bc2f646b47ade202c969df088d3f0ba5 (patch)
tree4e2fe29877a35fe6f4ba6a17921a6a2e6b93ffa8
parentc118ee96abdf9c6399fa70954fc53fa55f5fa54b (diff)
downloadgs201-sepolicy-a4fa4427bc2f646b47ade202c969df088d3f0ba5.tar.gz
Fix rlsservice sepolicy
Allows bugreport generation Bug: 315255760 Bug: 309379465 Test: abd bugreport & ensure lack of rls avc denied logs Change-Id: Ic390d6ddd6bac78e5979c78bc6d02262f08b3468
-rw-r--r--tracking_denials/bug_map1
-rw-r--r--whitechapel_pro/dumpstate.te2
-rw-r--r--whitechapel_pro/rlsservice.te4
3 files changed, 5 insertions, 2 deletions
diff --git a/tracking_denials/bug_map b/tracking_denials/bug_map
index 1797751..3972629 100644
--- a/tracking_denials/bug_map
+++ b/tracking_denials/bug_map
@@ -1,4 +1,3 @@
-dumpstate rlsservice binder b/309379465
hal_face_default traced_producer_socket sock_file b/305600808
hal_power_default hal_power_default capability b/237492146
incidentd debugfs_wakeup_sources file b/282626428
diff --git a/whitechapel_pro/dumpstate.te b/whitechapel_pro/dumpstate.te
index eaab9b2..da71a84 100644
--- a/whitechapel_pro/dumpstate.te
+++ b/whitechapel_pro/dumpstate.te
@@ -13,4 +13,4 @@ allow dumpstate modem_efs_file:dir r_dir_perms;
allow dumpstate modem_userdata_file:dir r_dir_perms;
allow dumpstate modem_img_file:dir r_dir_perms;
allow dumpstate fuse:dir search;
-
+allow dumpstate rlsservice:binder call; \ No newline at end of file
diff --git a/whitechapel_pro/rlsservice.te b/whitechapel_pro/rlsservice.te
index 967389a..e531b0d 100644
--- a/whitechapel_pro/rlsservice.te
+++ b/whitechapel_pro/rlsservice.te
@@ -32,3 +32,7 @@ allow rlsservice apex_info_file:file r_file_perms;
# Allow read camera property
get_prop(rlsservice, vendor_camera_prop);
+
+# Allow rlsservice bugreport generation
+allow rlsservice dumpstate:fd use;
+allow rlsservice dumpstate:fifo_file write; \ No newline at end of file