android_device_xiaomi_sdm66.../sepolicy/vendor/init.te
Alcatraz323 68c470f248 sdm660-common: sepolicy: address bunch of denials
* suppress bunch of capability denials, they are harmless and managed by aosp, if it should be fixed, aosp will do
* correct some typo

Signed-off-by: pix106 <sbordenave@gmail.com>
2023-08-22 08:44:53 +02:00

35 lines
1 KiB
Text

get_prop(init, exported_default_prop)
allow init adsprpcd_file:file mounton;
allow init apex_metadata_file:lnk_file read;
allow init socket_device:sock_file { unlink setattr create };
allow init sysfs_graphics:file { read open };
allow init sysfs_graphics:lnk_file read;
allow init sysfs_battery_supply:file setattr;
allow init vendor_default_prop:property_service set;
allow init sysfs_info:file { open read };
allow init {
bt_firmware_file
firmware_file
}:filesystem getattr;
allow init firmware_file:filesystem { getattr };
allow init bt_firmware_file:filesystem { getattr };
allow init apex_metadata_file:lnk_file { read };
# Vibrator
allow init sysfs_leds:file { rw_file_perms };
allow init sysfs:file { setattr };
allow init debugfs_tracing_debug:dir { mounton };
allow init sysfs_emmc_host:file rw_file_perms;
allow init system_file:file mounton;
allow init {
vendor_configs_file
vendor_framework_file
vendor_app_file
vendor_overlay_file
}:file mounton;
allow init hal_fingerprint_sdm660:process ptrace;