From 657e2647424f4709bc42d048f5dd077b27c3717c Mon Sep 17 00:00:00 2001 From: pix106 Date: Mon, 2 Jan 2023 12:59:14 +0100 Subject: [PATCH] sdm660-common: sepolicy: allow platform_app to read config.gz type=1400 audit(0.0:2767): avc: denied { read } for name="config.gz" dev="proc" ino=4026532183 scontext=u:r:platform_app:s0:c512,c768 tcontext=u:object_r:config_gz:s0 tclass=file permissive=0 app=com.android.launcher3 --- sepolicy/private/platform_app.te | 2 ++ 1 file changed, 2 insertions(+) diff --git a/sepolicy/private/platform_app.te b/sepolicy/private/platform_app.te index 225be2f5..1196be58 100644 --- a/sepolicy/private/platform_app.te +++ b/sepolicy/private/platform_app.te @@ -1,2 +1,4 @@ get_prop(platform_app, exported_camera_prop) r_dir_file(platform_app, sysfs_zram) + +allow platform_app config_gz:file r_file_perms;