Files
device_xiaomi_miatoll/sepolicy/vendor/hal_fingerprint_default.te
Sebastiano Barezzi 053d81bf4b sm6250-common: sepolicy: Don't grant system_server access to fingerprint props
Change-Id: I4f391e43a80c25d7fcedde12a70b3215913fcfd2
2022-08-26 18:27:17 +00:00

34 lines
935 B
Plaintext

typeattribute hal_fingerprint_default data_between_core_and_vendor_violators;
allow hal_fingerprint_default fingerprint_data_file:dir rw_dir_perms;
allow hal_fingerprint_default fingerprint_data_file:file create_file_perms;
allow hal_fingerprint_default {
fingerprint_device
input_device
tee_device
uhid_device
}: chr_file rw_file_perms;
allow hal_fingerprint_default self:netlink_socket create_socket_perms_no_ioctl;
allow hal_fingerprint_default {
input_device
vendor_sysfs_graphics
sysfs_msm_subsys
}: dir r_dir_perms;
allow hal_fingerprint_default {
vendor_sysfs_fingerprint
vendor_sysfs_fps_attr
vendor_sysfs_graphics
sysfs_msm_subsys
}: file rw_file_perms;
r_dir_file(hal_fingerprint_default, firmware_file)
set_prop(hal_fingerprint_default, vendor_fingerprint_prop)
allow hal_fingerprint_default vendor_sysfs_spss:dir { search };
allow hal_fingerprint_default vendor_sysfs_spss:file { open read };