sanders: Address some denials
This commit is contained in:
committed by
therootlord
parent
0df4237dd3
commit
05af13d217
4
sepolicy/hal_camera_default.te
Normal file
4
sepolicy/hal_camera_default.te
Normal file
@@ -0,0 +1,4 @@
|
|||||||
|
allow hal_camera_default gpu_device:dir r_dir_perms;
|
||||||
|
allow hal_camera_default gpu_device:file r_file_perms;
|
||||||
|
allow hal_camera_default hal_configstore_ISurfaceFlingerConfigs:hwservice_manager find;
|
||||||
|
allow hal_camera_default hal_configstore_default:binder call;
|
||||||
@@ -23,3 +23,6 @@ allow mm-qcamerad init:unix_stream_socket { read write };
|
|||||||
allow mm-qcamerad sysfs_graphics:file { open read };
|
allow mm-qcamerad sysfs_graphics:file { open read };
|
||||||
|
|
||||||
allow mm-qcamerad hal_sensors_default:unix_stream_socket { read write };
|
allow mm-qcamerad hal_sensors_default:unix_stream_socket { read write };
|
||||||
|
|
||||||
|
allow mm-qcamerad hal_configstore_ISurfaceFlingerConfigs:hwservice_manager find;
|
||||||
|
allow mm-qcamerad hal_configstore_default:binder call;
|
||||||
|
|||||||
@@ -1,4 +1,5 @@
|
|||||||
get_prop(platform_app, camera_prop);
|
get_prop(platform_app, camera_prop);
|
||||||
|
get_prop(platform_app, qemu_hw_mainkeys_prop);
|
||||||
binder_call(platform_app, hal_sensors_default);
|
binder_call(platform_app, hal_sensors_default);
|
||||||
|
|
||||||
allow platform_app rootfs:dir getattr;
|
allow platform_app rootfs:dir getattr;
|
||||||
|
|||||||
@@ -2,4 +2,5 @@ allow priv_app device:dir r_dir_perms;
|
|||||||
allow priv_app persist_file:filesystem getattr;
|
allow priv_app persist_file:filesystem getattr;
|
||||||
allow priv_app proc_interrupts:file { open read getattr };
|
allow priv_app proc_interrupts:file { open read getattr };
|
||||||
allow priv_app proc_modules:file { open read getattr };
|
allow priv_app proc_modules:file { open read getattr };
|
||||||
get_prop(priv_app, adspd_prop);
|
get_prop(priv_app, adspd_prop);
|
||||||
|
get_prop(priv_app, qemu_hw_mainkeys_prop);
|
||||||
Reference in New Issue
Block a user