sdm660-common: sepolicy: Address vendor_init persist_file denials
avc: denied { read } for comm="init" name="persist" dev="mmcblk0p13" ino=47 scontext=u:r:vendor_init:s0 tcontext=u:object_r:persist_file:s0 tclass=lnk_file permissive=0 Signed-off-by: pix106 <sbordenave@gmail.com>
This commit is contained in:
parent
8193f9632b
commit
837f5ca200
1 changed files with 1 additions and 0 deletions
1
sepolicy/vendor/vendor_init.te
vendored
1
sepolicy/vendor/vendor_init.te
vendored
|
@ -7,6 +7,7 @@ allow vendor_init {
|
||||||
}:dir { create search getattr open read setattr ioctl write add_name remove_name rmdir relabelfrom };
|
}:dir { create search getattr open read setattr ioctl write add_name remove_name rmdir relabelfrom };
|
||||||
|
|
||||||
allow vendor_init tee_device:chr_file getattr;
|
allow vendor_init tee_device:chr_file getattr;
|
||||||
|
allow vendor_init persist_file:lnk_file r_file_perms;
|
||||||
allow vendor_init proc:file w_file_perms;
|
allow vendor_init proc:file w_file_perms;
|
||||||
|
|
||||||
get_prop(vendor_init, hal_fingerprint_prop)
|
get_prop(vendor_init, hal_fingerprint_prop)
|
||||||
|
|
Loading…
Reference in a new issue