Loading common/private/netd.te 0 → 100644 +1 −0 Original line number Diff line number Diff line allow netd platform_app:unix_stream_socket connectto; common/private/platform_app.te +11 −0 Original line number Diff line number Diff line Loading @@ -9,3 +9,14 @@ hal_client_domain(platform_app, hal_lineage_livedisplay) # Allow PowerShare HAL service to be found hal_client_domain(platform_app, hal_lineage_powershare) # allow platform_app to create named pipes (used for realm support) allow platform_app fuse:fifo_file create; allow platform_app app_data_file:fifo_file create_file_perms; allow platform_app app_data_file:fifo_file open; allow platform_app rs_exec:file rx_file_perms; # Allow platform apps to execute files in /data allow platform_app app_data_file:file execute; allow platform_app app_data_file:{ lnk_file sock_file fifo_file } create_file_perms; common/private/updater_app.te +1 −0 Original line number Diff line number Diff line Loading @@ -9,6 +9,7 @@ binder_call(updater_app, update_engine) allow updater_app app_api_service:service_manager find; allow updater_app recovery_service:service_manager find; allow updater_app system_api_service:service_manager find; allow updater_app system_update_service:service_manager find; allow updater_app update_engine_service:service_manager find; allow updater_app app_data_file:dir create_dir_perms; Loading Loading
common/private/netd.te 0 → 100644 +1 −0 Original line number Diff line number Diff line allow netd platform_app:unix_stream_socket connectto;
common/private/platform_app.te +11 −0 Original line number Diff line number Diff line Loading @@ -9,3 +9,14 @@ hal_client_domain(platform_app, hal_lineage_livedisplay) # Allow PowerShare HAL service to be found hal_client_domain(platform_app, hal_lineage_powershare) # allow platform_app to create named pipes (used for realm support) allow platform_app fuse:fifo_file create; allow platform_app app_data_file:fifo_file create_file_perms; allow platform_app app_data_file:fifo_file open; allow platform_app rs_exec:file rx_file_perms; # Allow platform apps to execute files in /data allow platform_app app_data_file:file execute; allow platform_app app_data_file:{ lnk_file sock_file fifo_file } create_file_perms;
common/private/updater_app.te +1 −0 Original line number Diff line number Diff line Loading @@ -9,6 +9,7 @@ binder_call(updater_app, update_engine) allow updater_app app_api_service:service_manager find; allow updater_app recovery_service:service_manager find; allow updater_app system_api_service:service_manager find; allow updater_app system_update_service:service_manager find; allow updater_app update_engine_service:service_manager find; allow updater_app app_data_file:dir create_dir_perms; Loading