universal7870: update sepolicy (wip)

This commit is contained in:
Astrako 2020-03-26 11:38:15 +01:00 committed by Alejandro
parent 841f56ecbf
commit 4cd64b76bd
46 changed files with 515 additions and 184 deletions

View file

@ -1,10 +1,11 @@
# /dev/mbin0
allow system_server emmcblk_device:dir search;
allow system_server emmcblk_device:blk_file { read write open ioctl getattr };
# /efs
allow system_server efs_file:dir r_dir_perms;
# /efs/FactoryApp/gyro_cal_data
# /efs/gyro_cal_data
allow system_server sensor_efs_file:file r_file_perms;
# /data/system/gps/.gps.interface.pipe.*
@ -15,7 +16,7 @@ allow system_server gps_data_file:fifo_file create_file_perms;
allow system_server gps_data_file:dir rw_dir_perms;
# /data/system/gps/chip.info
allow system_server gps_data_file:file create_file_perms;
allow system_server gps_data_file:file r_file_perms;
# /efs/prox_cal
allow system_server efs_file:file r_file_perms;
@ -30,22 +31,27 @@ allow system_server wifi_efs_file:dir r_dir_perms;
allow system_server wifi_efs_file:file r_file_perms;
# mDNIE
allow system_server sysfs_mdnie_writable:lnk_file rw_file_perms;
allow system_server sysfs_mdnie_writable:dir r_dir_perms;
allow system_server sysfs_mdnie_writable:file rw_file_perms;
allow system_server sysfs_mdnie:lnk_file rw_file_perms;
allow system_server sysfs_mdnie:file rw_file_perms;
# memtrack HAL
allow system_server debugfs:dir r_dir_perms;
allow system_server debugfs:file r_file_perms;
# sensor HAL
allow system_server sensor_device:chr_file rw_file_perms;
allow system_server baro_delta_factoryapp_efs_file:file r_file_perms;
allow system_server sensor_factoryapp_efs_file:file r_file_perms;
# sysfs
allow system_server sysfs_brightness:file write;
allow system_server sysfs_input:file write;
allow system_server sysfs_sec:file write;
allow system_server sysfs_devices_system_cpu:file write;
allow system_server sysfs_virtual:file write;
# /data/system/gps/xtraee.bin
allow system_server gps_data_file:file create_file_perms;
allow system_server emmcblk_device:blk_file { getattr ioctl open read write };
allow system_server gps_data_file:dir { add_name remove_name write search };
allow system_server gps_data_file:file { create setattr unlink write };
allow system_server gpsd:unix_stream_socket connectto;
allow system_server sysfs_sec:dir search;
allow system_server sysfs_sec:lnk_file read;
allow system_server crash_dump:process getpgid;
allow system_server unlabeled:dir write;
unix_socket_connect(system_server, property, gpsd)
allow system_server proc:file { read open getattr };