diff --git a/sepolicy/vendor/hal_bootctl_default.te b/sepolicy/vendor/hal_bootctl_default.te new file mode 100644 index 0000000000000000000000000000000000000000..84d58d3ce87497178cbd67595c95298327711acd --- /dev/null +++ b/sepolicy/vendor/hal_bootctl_default.te @@ -0,0 +1 @@ +allow hal_bootctl_default uefi_block_device:blk_file getattr; diff --git a/sepolicy/vendor/update_engine.te b/sepolicy/vendor/update_engine.te new file mode 100644 index 0000000000000000000000000000000000000000..29464bb07c8a9d9074f2173ba9e2e7cd1d1648ae --- /dev/null +++ b/sepolicy/vendor/update_engine.te @@ -0,0 +1,10 @@ +allow update_engine { + firmware_file + bt_firmware_file +}:filesystem getattr; + +allow update_engine { + adsprpcd_file + firmware_file + metadata_file +}:dir search;