diff options
author | John Stultz <jstultz@google.com> | 2022-04-18 20:05:06 +0000 |
---|---|---|
committer | Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com> | 2022-04-18 20:05:06 +0000 |
commit | a0aed144e6e21cda425fe09a55c6207ef5a87901 (patch) | |
tree | b6176c9e790896f9ef06592b8a1bd7afb58355cc | |
parent | bd0989fb5d738b34141b355dc0833c73dc1a6254 (diff) | |
parent | e49a40f4f182255f488f05256e8d3950ab5ab190 (diff) | |
download | dragonboard-a0aed144e6e21cda425fe09a55c6207ef5a87901.tar.gz |
dragonboard: sepolicy: Add sepolicy rules to fix problems seen adb remount overlays am: a58e74ea06 am: 2372d29d25 am: dc2dc122dc am: e49a40f4f1
Original change: https://android-review.googlesource.com/c/device/linaro/dragonboard/+/2063214
Change-Id: Idb117492bc1f58d27452a9a80cbc3e7121b835e7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
-rw-r--r-- | sepolicy/kernel.te | 6 | ||||
-rw-r--r-- | sepolicy/surfaceflinger.te | 1 | ||||
-rw-r--r-- | sepolicy/system_server.te | 2 |
3 files changed, 8 insertions, 1 deletions
diff --git a/sepolicy/kernel.te b/sepolicy/kernel.te index 3fad122..176d6f6 100644 --- a/sepolicy/kernel.te +++ b/sepolicy/kernel.te @@ -2,6 +2,10 @@ allow kernel device:chr_file { create setattr }; allow kernel device:dir { add_name create write }; allow kernel self:capability mknod; -allow kernel vendor_file:file { open read }; +allow kernel vendor_file:file { open read getattr}; +allow kernel vendor_file:dir read; allow kernel self:system module_request; allow vendor_init kernel:system module_request; +allow kernel sepolicy_file:file getattr; +allow kernel system_bootstrap_lib_file:dir getattr; +allow kernel system_bootstrap_lib_file:file getattr; diff --git a/sepolicy/surfaceflinger.te b/sepolicy/surfaceflinger.te index 17b66a8..9bffa3f 100644 --- a/sepolicy/surfaceflinger.te +++ b/sepolicy/surfaceflinger.te @@ -1 +1,2 @@ gpu_access(surfaceflinger) +allow surfaceflinger vendor_file:dir read; diff --git a/sepolicy/system_server.te b/sepolicy/system_server.te index 80957cc..e801436 100644 --- a/sepolicy/system_server.te +++ b/sepolicy/system_server.te @@ -1 +1,3 @@ gpu_access(system_server) +allow system_server wifi_hal_prop:file {open read getattr map}; +allow system_server vendor_file:dir read; |