sm6250-common: sepolicy: Address last remaining denials

Signed-off-by: SonalSingh18 <sonal.singh.19993@gmail.com>
This commit is contained in:
SonalSingh18 2021-01-24 20:19:16 +05:30 committed by 4PERTURE
parent 757912aaad
commit 84f48b50e1
18 changed files with 23 additions and 3 deletions

View File

@ -1,2 +1,3 @@
allow system_suspend sysfs:dir { open read }; allow system_suspend sysfs:dir { open read };
dontaudit system_suspend sysfs:file { getattr open read }; allow system_suspend sysfs:file { getattr };
dontaudit system_suspend sysfs:file { open read };

1
sepolicy/vendor/batterysecret.te vendored Normal file
View File

@ -0,0 +1 @@
allow batterysecret kmsg_device:chr_file { getattr };

1
sepolicy/vendor/bluetooth.te vendored Normal file
View File

@ -0,0 +1 @@
allow bluetooth incremental_prop:file { read };

2
sepolicy/vendor/hal_camera_default.te vendored Normal file
View File

@ -0,0 +1,2 @@
allow hal_camera_default mnt_vendor_file:dir { search };
allow hal_camera_default proc_stat:file { read };

View File

@ -23,4 +23,3 @@ binder_call(hal_fingerprint_default, hal_perf_default)
r_dir_file(hal_fingerprint_default, firmware_file) r_dir_file(hal_fingerprint_default, firmware_file)
set_prop(hal_fingerprint_default, hal_fingerprint_prop) set_prop(hal_fingerprint_default, hal_fingerprint_prop)
dontaudit hal_fingerprint_default storage_file:dir search; dontaudit hal_fingerprint_default storage_file:dir search;

View File

@ -1 +1 @@
allow hal_health_default sysfs:file { open read }; allow hal_health_default sysfs:file { getattr open read };

1
sepolicy/vendor/radio.te vendored Normal file
View File

@ -0,0 +1 @@
allow radio gpuservice:binder { call };

View File

@ -1,2 +1,5 @@
allow system_app vendor_default_prop:file { getattr open read }; allow system_app vendor_default_prop:file { getattr open read };
allow system_app vendor_default_prop:file {map}; allow system_app vendor_default_prop:file {map};
allow system_app vendor_sysfs_graphics:file { getattr open read };
allow system_app vendor_sysfs_msm_perf:dir { search };
allow system_app apk_data_file:dir { write };

1
sepolicy/vendor/vendor_hal_gnss_qti vendored Normal file
View File

@ -0,0 +1 @@
allow vendor_hal_gnss_qti sysfs:file { read };

1
sepolicy/vendor/vendor_ims.te vendored Normal file
View File

@ -0,0 +1 @@
allow vendor_ims sysfs:file { read };

View File

@ -10,3 +10,6 @@ allow init adsprpcd_file:file mounton;
set_prop(vendor_init, vendor_freq_prop) set_prop(vendor_init, vendor_freq_prop)
set_prop(vendor_init, vendor_camera_prop) set_prop(vendor_init, vendor_camera_prop)
set_prop(vendor_init, camera_prop) set_prop(vendor_init, camera_prop)
allow vendor_init persist_debug_prop:file { read };
allow vendor_init default_prop:file { read };

1
sepolicy/vendor/vendor_netmgrd vendored Normal file
View File

@ -0,0 +1 @@
allow vendor_netmgrd sysfs:file { read };

1
sepolicy/vendor/vendor_per_mgr vendored Normal file
View File

@ -0,0 +1 @@
allow vendor_per_mgr sysfs:file { read };

1
sepolicy/vendor/vendor_per_proxy vendored Normal file
View File

@ -0,0 +1 @@
allow vendor_per_proxy sysfs:file { read };

1
sepolicy/vendor/vendor_port-bridge vendored Normal file
View File

@ -0,0 +1 @@
allow vendor_port-bridge sysfs:file { read };

1
sepolicy/vendor/vendor_rmt_storage vendored Normal file
View File

@ -0,0 +1 @@
allow vendor_rmt_storage sysfs:file { read };

View File

@ -0,0 +1 @@
allow vendor_sysfs_battery_supply vendor_sysfs_battery_supply:dir { read };

1
sepolicy/vendor/vendor_wcnss_service vendored Normal file
View File

@ -0,0 +1 @@
allow vendor_wcnss_service sysfs:file { read };