Commit 599cddda authored by TARKZiM's avatar TARKZiM Committed by Bernhard Thoben
Browse files

kitakami-common: sepolicy: Address Dumpstate HAL denials

* Also address vendor SPL props denial.

Change-Id: I1a0875a06a7a5f26f30270fc0902e236293b666e
parent 60a17a8a
type hal_dumpstate_impl, domain;
type hal_dumpstate_impl_exec, exec_type, file_type, vendor_file_type;
init_daemon_domain(hal_dumpstate_impl)
allow hal_dumpstate_impl hal_dumpstate_impl_exec:file execute_no_trans;
allow hal_dumpstate_impl hwservicemanager:binder { call transfer };
allow hal_dumpstate_impl hwservicemanager_prop:file { getattr map open read };
allow hal_dumpstate_impl hidl_base_hwservice:hwservice_manager add;
allow hal_dumpstate_impl hal_dumpstate_hwservice:hwservice_manager { add find };
allow hwservicemanager hal_drm_clearkey:dir search;
allow hwservicemanager hal_drm_clearkey:file { open read };
allow hwservicemanager hal_drm_clearkey:process getattr;
allow hwservicemanager hal_dumpstate_impl:dir rw_dir_perms;
allow hwservicemanager hal_dumpstate_impl:file rw_file_perms;
allow hwservicemanager hal_dumpstate_impl:binder { call transfer };
allow hwservicemanager hal_dumpstate_impl:process getattr;
allow hwservicemanager init:dir search;
allow hwservicemanager init:file { open read };
allow hwservicemanager init:process getattr;
allow system_app default_android_service:service_manager find;
allow system_app hal_power_default:binder call;
allow system_app hal_dumpstate_impl:binder call;
allow system_app init:binder call;
allow system_app installd:binder call;
allow system_app iorapd:binder call;
......
......@@ -2,4 +2,4 @@ allow system_server exported_camera_prop:file { getattr open read };
allow system_server hal_light_default:process signal;
allow system_server userspace_reboot_config_prop:file { getattr open read };
allow system_server userspace_reboot_exported_prop:file { getattr open read };
allow system_server vendor_security_patch_level_prop:file { getattr open read };
allow system_server vendor_security_patch_level_prop:file r_file_perms;
Supports Markdown
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment