android_device_samsung_univ.../sepolicy/system_server.te
Hendra Manudinata f0e4521a9f
universal7570: import sepolicy from 7870
The sepolicy before seems to be broken

Change-Id: I890a28429f03e47a183a0a0b755987f3495994c3
2021-03-13 05:09:06 +07:00

57 lines
1.9 KiB
Text

# /efs
allow system_server efs_file:dir r_dir_perms;
# /efs/gyro_cal_data
allow system_server sensor_efs_file:file r_file_perms;
# /data/system/gps/.gps.interface.pipe.*
type_transition system_server system_data_file:fifo_file gps_data_file ".flp.interface.pipe.to_gpsd";
type_transition system_server system_data_file:fifo_file gps_data_file ".gps.interface.pipe.to_gpsd";
type_transition system_server system_data_file:fifo_file gps_data_file ".gps.interface.pipe.to_jni";
allow system_server gps_data_file:fifo_file create_file_perms;
allow system_server gps_data_file:dir rw_dir_perms;
# /data/system/gps/chip.info
allow system_server gps_data_file:file r_file_perms;
# /efs/prox_cal
allow system_server efs_file:file r_file_perms;
# /efs/FactoryApp
allow system_server app_efs_file:dir r_dir_perms;
allow system_server app_efs_file:file r_file_perms;
# WifiMachine
allow system_server self:capability sys_module;
allow system_server wifi_efs_file:dir r_dir_perms;
allow system_server wifi_efs_file:file r_file_perms;
# mDNIE
allow system_server sysfs_mdnie:lnk_file rw_file_perms;
#allow system_server sysfs_mdnie:dir rw_dir_perms;
allow system_server sysfs_mdnie:file rw_file_perms;
# memtrack HAL
allow system_server debugfs:dir r_dir_perms;
# sensor HAL
allow system_server sensor_device:chr_file rw_file_perms;
allow system_server baro_delta_factoryapp_efs_file:file r_file_perms;
allow system_server sensor_factoryapp_efs_file:file r_file_perms;
allow system_server sysfs_sensors:file rw_file_perms;
# /data/system/gps/xtraee.bin
allow system_server gps_data_file:file create_file_perms;
# Bluetooth buildprop
get_prop(system_server, bluetooth_prop)
# Grpahics sysfs
allow system_server sysfs_graphics:file rw_file_perms;
# Input sysfs
allow system_server sysfs_input:file rw_file_perms;
allow system_server proc_input_devices:file r_file_perms;
# unix_socket_connect(system_server, property, gpsd)