sanders: sepol: update sepolicy
-ref: https://github.com/crdroidandroid/android_device_motorola_sanders/tree/10.0-20200126 Signed-off-by: ronaxdevil <pratabidya.007@gmail.com>
This commit is contained in:
14
sepolicy/vendor/cameraserver.te
vendored
14
sepolicy/vendor/cameraserver.te
vendored
@@ -25,7 +25,7 @@ allow cameraserver media_rw_data_file:file { create read write open };
|
||||
allow cameraserver cameraserver:process { execmem };
|
||||
|
||||
####
|
||||
#allow cameraserver debug_prop:file { r_file_perms };
|
||||
allow cameraserver debug_prop:file { r_file_perms };
|
||||
allow cameraserver debug_prop:property_service set;
|
||||
|
||||
#######
|
||||
@@ -33,7 +33,7 @@ allow cameraserver debug_prop:property_service set;
|
||||
#allow cameraserver persist_file:file setattr;
|
||||
allow cameraserver shell_exec:file { read open execute };
|
||||
allow cameraserver self:socket create;
|
||||
#allow cameraserver camera_prop:property_service set;
|
||||
allow cameraserver camera_prop:property_service set;
|
||||
allow cameraserver init:unix_stream_socket connectto;
|
||||
allow cameraserver property_socket:sock_file write;
|
||||
#allow cameraserver cameraserver:socket { { getattr read ioctl lock } { append write lock } };
|
||||
@@ -45,9 +45,13 @@ allow cameraserver debugfs:dir { read open };
|
||||
allow cameraserver nfc_data_file:file { open write };
|
||||
allow cameraserver socket_device:sock_file write;
|
||||
|
||||
#allow cameraserver hal_perf_default:binder call;
|
||||
allow cameraserver hal_perf_default:binder call;
|
||||
|
||||
#allow cameraserver sysfs_battery_supply:dir search;
|
||||
#allow cameraserver sysfs_battery_supply:file { getattr open read };
|
||||
allow cameraserver sysfs_battery_supply:dir search;
|
||||
allow cameraserver sysfs_battery_supply:file { getattr open read };
|
||||
|
||||
allow cameraserver camera_bgproc_service:service_manager { add find };
|
||||
allow cameraserver self:netlink_kobject_uevent_socket { read bind create setopt };
|
||||
allow cameraserver default_android_service:service_manager find;
|
||||
allow cameraserver rootfs:lnk_file getattr;
|
||||
allow cameraserver init:unix_dgram_socket { sendto };
|
||||
|
||||
Reference in New Issue
Block a user