sepolicy: Add create socket file permission for vendor_wcnss_service

cnss_cli use unix socket to communicate with cnss-daemon.
cnss-daemon need create unix socket server file when init.

Change-Id: Ibbe1eb1f418da17c0155a0663f6a94d8777ef80f
This commit is contained in:
Baowei Liu 2021-11-22 14:07:21 +08:00 committed by Gerrit - the friendly Code Review server
parent f6efb39ffb
commit 639219bf3a

View file

@ -32,3 +32,10 @@ unix_socket_connect(vendor_wcnss_service, vendor_wigignpt, vendor_wigignpt)
allow vendor_wcnss_service self:capability net_admin;
allow vendor_wcnss_service kmsg_device:chr_file { write open };
allow vendor_wcnss_service proc_net:file read;
allow vendor_wcnss_service vendor_wifi_vendor_wpa_socket:dir create_dir_perms;
allow vendor_wcnss_service vendor_wifi_vendor_wpa_socket:dir r_dir_perms;
allow vendor_wcnss_service vendor_wifi_vendor_wpa_socket:sock_file create_file_perms;
allow vendor_wcnss_service vendor_wifi_vendor_wpa_socket:sock_file rw_file_perms;
allow vendor_wcnss_service vendor_wifi_vendor_wpa_socket:file create_file_perms;
allow vendor_wcnss_service vendor_wifi_vendor_wpa_socket:file rw_file_perms;