From 1da868148d75fb8deca717352fb243bcbf260e68 Mon Sep 17 00:00:00 2001 From: Nick Bray Date: Mon, 17 Apr 2017 14:51:00 -0700 Subject: Change levelFrom=all to levelFrom=user VrCore was trying to access .../com.google.android.gms/app_chimera, and this was causing an avc denial due to multi-level security. Bug: 36367417 Test: can pair controler Change-Id: I5b79dc279f099a29bc1957110fa8bea1cdcd652c --- vrcore/sepolicy/seapp_contexts | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) (limited to 'vrcore') diff --git a/vrcore/sepolicy/seapp_contexts b/vrcore/sepolicy/seapp_contexts index 7d28d38..229d486 100644 --- a/vrcore/sepolicy/seapp_contexts +++ b/vrcore/sepolicy/seapp_contexts @@ -1,4 +1,4 @@ # The default domain for vrcore processes. -user=_app seinfo=vrcore name=com.google.vr.vrcore* domain=vrcore_app type=app_data_file levelFrom=all +user=_app seinfo=vrcore name=com.google.vr.vrcore* domain=vrcore_app type=app_data_file levelFrom=user # A fallback in case vrcore is missing something critical that untrusted_app provides. -user=_app seinfo=vrcore name=com.google.vr.vrcore:app domain=untrusted_app type=app_data_file levelFrom=all +user=_app seinfo=vrcore name=com.google.vr.vrcore:app domain=untrusted_app type=app_data_file levelFrom=user -- cgit v1.2.3