From 347bc3181eb3de99bfc7ed3fa641e2d0eea7f2a6 Mon Sep 17 00:00:00 2001 From: pix106 Date: Tue, 21 Sep 2021 08:22:55 +0200 Subject: [PATCH] sdm660-common: clover: sepolicy: Adress no fingerprint denials avc: denied { mounton } for comm="init" path="/vendor/etc/permissions/android.hardware.fingerprint.xml" dev="mmcblk0p14" ino=513 scontext=u:r:init:s0 tcontext=u:object_r:vendor_configs_file:s0 tclass=file permissive=0 avc: denied { mounton } for comm="init" path="/vendor/framework/com.fingerprints.extension.jar" dev="mmcblk0p14" ino=651 scontext=u:r:init:s0 tcontext=u:object_r:vendor_framework_file:s0 tclass=file permissive=0 avc: denied { mounton } for comm="init" path="/vendor/etc/permissions/com.fingerprints.extension.xml" dev="mmcblk0p14" ino=546 scontext=u:r:init:s0 tcontext=u:object_r:vendor_configs_file:s0 tclass=file permissive=0 avc: denied { mounton } for comm="init" path="/vendor/app/FingerprintExtensionService/FingerprintExtensionService.apk" dev="mmcblk0p14" ino=20 scontext=u:r:init:s0 tcontext=u:object_r:vendor_app_file:s0 tclass=file permissive=0 Signed-off-by: pix106 --- sepolicy/vendor/init.te | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/sepolicy/vendor/init.te b/sepolicy/vendor/init.te index 4364ee09..4e01a52f 100644 --- a/sepolicy/vendor/init.te +++ b/sepolicy/vendor/init.te @@ -22,3 +22,8 @@ allow init sysfs:file { setattr }; allow init debugfs_tracing_debug:dir { mounton }; allow init system_file:file mounton; +allow init { + vendor_configs_file + vendor_framework_file + vendor_app_file +}:file mounton;