android_device_samsung_univ.../sepolicy/system_server.te
2020-06-30 20:58:08 +02:00

57 lines
2 KiB
Text

# /dev/mbin0
allow system_server emmcblk_device:dir search;
allow system_server emmcblk_device:blk_file { read write open ioctl getattr };
# /efs
allow system_server efs_file:dir r_dir_perms;
# /efs/gyro_cal_data
allow system_server sensor_efs_file:file r_file_perms;
# /data/system/gps/.gps.interface.pipe.*
type_transition system_server system_data_file:fifo_file gps_data_file ".flp.interface.pipe.to_gpsd";
type_transition system_server system_data_file:fifo_file gps_data_file ".gps.interface.pipe.to_gpsd";
type_transition system_server system_data_file:fifo_file gps_data_file ".gps.interface.pipe.to_jni";
allow system_server gps_data_file:fifo_file create_file_perms;
allow system_server gps_data_file:dir rw_dir_perms;
# /data/system/gps/chip.info
allow system_server gps_data_file:file r_file_perms;
# /efs/prox_cal
allow system_server efs_file:file r_file_perms;
# /efs/FactoryApp
allow system_server app_efs_file:dir r_dir_perms;
allow system_server app_efs_file:file r_file_perms;
# WifiMachine
allow system_server self:capability { sys_module };
allow system_server wifi_efs_file:dir r_dir_perms;
allow system_server wifi_efs_file:file r_file_perms;
# mDNIE
allow system_server sysfs_mdnie:lnk_file rw_file_perms;
allow system_server sysfs_mdnie:file rw_file_perms;
# memtrack HAL
allow system_server debugfs:dir r_dir_perms;
# sensor HAL
allow system_server sensor_device:chr_file rw_file_perms;
allow system_server baro_delta_factoryapp_efs_file:file r_file_perms;
allow system_server sensor_factoryapp_efs_file:file r_file_perms;
# sysfs
allow system_server sysfs_brightness:file write;
allow system_server sysfs_input:file write;
allow system_server sysfs_sec:file write;
allow system_server sysfs_devices_system_cpu:file write;
allow system_server sysfs_virtual:file write;
# /data/system/gps/xtraee.bin
allow system_server gps_data_file:file create_file_perms;
unix_socket_connect(system_server, property, gpsd)
allow system_server proc:file { read open getattr };