sdm660-common: sepolicy: Address vendor_init persist_file denials

avc: denied { read } for comm="init" name="persist" dev="mmcblk0p13" ino=47 scontext=u:r:vendor_init:s0 tcontext=u:object_r:persist_file:s0 tclass=lnk_file permissive=0

Signed-off-by: pix106 <sbordenave@gmail.com>
This commit is contained in:
pix106 2021-09-10 14:00:33 +02:00
parent 8193f9632b
commit 837f5ca200

View file

@ -7,6 +7,7 @@ allow vendor_init {
}:dir { create search getattr open read setattr ioctl write add_name remove_name rmdir relabelfrom }; }:dir { create search getattr open read setattr ioctl write add_name remove_name rmdir relabelfrom };
allow vendor_init tee_device:chr_file getattr; allow vendor_init tee_device:chr_file getattr;
allow vendor_init persist_file:lnk_file r_file_perms;
allow vendor_init proc:file w_file_perms; allow vendor_init proc:file w_file_perms;
get_prop(vendor_init, hal_fingerprint_prop) get_prop(vendor_init, hal_fingerprint_prop)