From e41816077c2c3a8b990ffb38ec7ce23ffb9eae59 Mon Sep 17 00:00:00 2001 From: pix106 Date: Wed, 16 Nov 2022 08:16:04 +0100 Subject: [PATCH] sdm660-common: sepolicy: allow apexd to read apex_metadata_file * type=1400 audit(115448057.189:5): avc: denied { read } for comm="apexd" name="apex" dev="mmcblk0p63" ino=32 scontext=u:r:apexd:s0 tcontext=u:object_r:apex_metadata_file:s0 tclass=lnk_file permissive=0 --- sepolicy/vendor/apexd.te | 1 + 1 file changed, 1 insertion(+) create mode 100644 sepolicy/vendor/apexd.te diff --git a/sepolicy/vendor/apexd.te b/sepolicy/vendor/apexd.te new file mode 100644 index 00000000..7e3fde6d --- /dev/null +++ b/sepolicy/vendor/apexd.te @@ -0,0 +1 @@ +allow apexd apex_metadata_file:lnk_file r_file_perms;