sanders: update sepolicy.
-Fix Neverallows. -Fix missing type. -Fix type attributes. Signed-off-by: Ashwin R C <ashwin2001achu@gmail.com> Signed-off-by: ronaxdevil <pratabidya.007@gmail.com>
This commit is contained in:
5
sepolicy/vendor/cameraserver.te
vendored
5
sepolicy/vendor/cameraserver.te
vendored
@@ -11,8 +11,6 @@ allow cameraserver sdcardfs:dir { read write open getattr add_name remove_name r
|
||||
allow cameraserver sdcardfs:file { create open read write unlink getattr };
|
||||
allow cameraserver storage_file:dir search;
|
||||
|
||||
allow cameraserver persist_file:file { read write open create getattr create_file_perms rw_file_perms };
|
||||
allow cameraserver persist_file:dir { read write open create_file_perms rw_file_perms search add_name create };
|
||||
allow cameraserver fuse:file { read write open create getattr create_file_perms rw_file_perms };
|
||||
allow cameraserver fuse:dir { read write open create_file_perms rw_file_perms search add_name create };
|
||||
allow cameraserver tmpfs:file { read write open create getattr create_file_perms rw_file_perms };
|
||||
@@ -24,8 +22,6 @@ allow cameraserver mnt_user_file:lnk_file r_file_perms;
|
||||
allow cameraserver media_rw_data_file:dir { open read search write add_name };
|
||||
allow cameraserver media_rw_data_file:file { create read write open };
|
||||
|
||||
allow cameraserver sysfs:file { open write };
|
||||
|
||||
allow cameraserver cameraserver:process { execmem };
|
||||
|
||||
####
|
||||
@@ -39,7 +35,6 @@ allow cameraserver shell_exec:file { read open execute };
|
||||
allow cameraserver self:socket create;
|
||||
allow cameraserver camera_prop:property_service set;
|
||||
allow cameraserver init:unix_stream_socket connectto;
|
||||
allow cameraserver sensors_persist_file:file { open read };
|
||||
allow cameraserver property_socket:sock_file write;
|
||||
#allow cameraserver cameraserver:socket { { getattr read ioctl lock } { append write lock } };
|
||||
allow cameraserver shell_exec:file { execute getattr };
|
||||
|
||||
Reference in New Issue
Block a user