diff options
author | Boon Jun Soh <boonjun@google.com> | 2023-12-08 18:54:45 +0800 |
---|---|---|
committer | Treehugger Robot <android-test-infra-autosubmit@system.gserviceaccount.com> | 2023-12-11 07:30:24 +0000 |
commit | a4fa4427bc2f646b47ade202c969df088d3f0ba5 (patch) | |
tree | 4e2fe29877a35fe6f4ba6a17921a6a2e6b93ffa8 | |
parent | c118ee96abdf9c6399fa70954fc53fa55f5fa54b (diff) | |
download | gs201-sepolicy-a4fa4427bc2f646b47ade202c969df088d3f0ba5.tar.gz |
Fix rlsservice sepolicy
Allows bugreport generation
Bug: 315255760
Bug: 309379465
Test: abd bugreport & ensure lack of rls avc denied logs
Change-Id: Ic390d6ddd6bac78e5979c78bc6d02262f08b3468
-rw-r--r-- | tracking_denials/bug_map | 1 | ||||
-rw-r--r-- | whitechapel_pro/dumpstate.te | 2 | ||||
-rw-r--r-- | whitechapel_pro/rlsservice.te | 4 |
3 files changed, 5 insertions, 2 deletions
diff --git a/tracking_denials/bug_map b/tracking_denials/bug_map index 1797751..3972629 100644 --- a/tracking_denials/bug_map +++ b/tracking_denials/bug_map @@ -1,4 +1,3 @@ -dumpstate rlsservice binder b/309379465 hal_face_default traced_producer_socket sock_file b/305600808 hal_power_default hal_power_default capability b/237492146 incidentd debugfs_wakeup_sources file b/282626428 diff --git a/whitechapel_pro/dumpstate.te b/whitechapel_pro/dumpstate.te index eaab9b2..da71a84 100644 --- a/whitechapel_pro/dumpstate.te +++ b/whitechapel_pro/dumpstate.te @@ -13,4 +13,4 @@ allow dumpstate modem_efs_file:dir r_dir_perms; allow dumpstate modem_userdata_file:dir r_dir_perms; allow dumpstate modem_img_file:dir r_dir_perms; allow dumpstate fuse:dir search; - +allow dumpstate rlsservice:binder call;
\ No newline at end of file diff --git a/whitechapel_pro/rlsservice.te b/whitechapel_pro/rlsservice.te index 967389a..e531b0d 100644 --- a/whitechapel_pro/rlsservice.te +++ b/whitechapel_pro/rlsservice.te @@ -32,3 +32,7 @@ allow rlsservice apex_info_file:file r_file_perms; # Allow read camera property get_prop(rlsservice, vendor_camera_prop); + +# Allow rlsservice bugreport generation +allow rlsservice dumpstate:fd use; +allow rlsservice dumpstate:fifo_file write;
\ No newline at end of file |