diff options
author | Bruce Beare <bruce.j.beare@intel.com> | 2015-10-23 21:16:12 -0700 |
---|---|---|
committer | Bruce Beare <bruce.j.beare@intel.com> | 2015-11-03 23:10:31 -0800 |
commit | 2f7415c5a2a19e36a2f4497f03d081041626842e (patch) | |
tree | 6ce0b8d3495b5b8ae74bcb6fe5e6aadeee9db9ab | |
parent | a7e9352d2976e87e72cb83b50d28186b5f42122b (diff) | |
download | edison-2f7415c5a2a19e36a2f4497f03d081041626842e.tar.gz |
Edison specific SELinux Rules
sensorservice access to sysfs and debugfs.
Label block devices used by update_engine.
Change-Id: I23f5ece685afb742c5028f3f1c38b5f3a7f440f3
Author: Bruce Beare <bruce.j.beare@intel.com>
Author: David Zeuthen <zeuthen@google.com>
Signed-off-by: Bruce Beare <bruce.j.beare@intel.com>
-rw-r--r-- | sepolicy/file_contexts | 5 | ||||
-rw-r--r-- | sepolicy/sensorservice.te | 6 |
2 files changed, 11 insertions, 0 deletions
diff --git a/sepolicy/file_contexts b/sepolicy/file_contexts new file mode 100644 index 0000000..1a73875 --- /dev/null +++ b/sepolicy/file_contexts @@ -0,0 +1,5 @@ +/dev/block/pci/pci0000:00/0000:00:01.0/by-name/misc u:object_r:misc_block_device:s0 +/dev/block/pci/pci0000:00/0000:00:01.0/by-name/boot_a u:object_r:boot_block_device:s0 +/dev/block/pci/pci0000:00/0000:00:01.0/by-name/system_a u:object_r:system_block_device:s0 +/dev/block/pci/pci0000:00/0000:00:01.0/by-name/boot_b u:object_r:boot_block_device:s0 +/dev/block/pci/pci0000:00/0000:00:01.0/by-name/system_b u:object_r:system_block_device:s0 diff --git a/sepolicy/sensorservice.te b/sepolicy/sensorservice.te new file mode 100644 index 0000000..8469954 --- /dev/null +++ b/sepolicy/sensorservice.te @@ -0,0 +1,6 @@ +# +# Sensorservice uses the sensors HAL... which needs sysfs file and i2c device access. +# + +allow sensorservice i2c_device:chr_file rw_file_perms; +allow sensorservice sysfs:file w_file_perms; |