Merge "sepolicy: Fix the AVC denials for system daemon"

This commit is contained in:
qctecmdr 2021-08-25 23:14:08 -07:00 committed by Gerrit - the friendly Code Review server
commit d7ee2be4ff
2 changed files with 2 additions and 2 deletions

2
legacy/vendor/common/qcomsysd.te vendored Executable file → Normal file
View file

@ -44,7 +44,7 @@ allow vendor_qcomsysd {
#Needed to get image info from socinfo
allow vendor_qcomsysd sysfs_socinfo:file w_file_perms;
allow vendor_qcomsysd self:capability { sys_boot };
allow vendor_qcomsysd self:capability { sys_boot kill };
allow vendor_qcomsysd self:qipcrtr_socket create_socket_perms_no_ioctl;
use_vendor_per_mgr(vendor_qcomsysd);
#allow qcomsysd access boot mode switch

2
qva/vendor/common/qcomsysd.te vendored Executable file → Normal file
View file

@ -42,7 +42,7 @@ r_dir_file(vendor_qcomsysd, vendor_sysfs_soc)
allow vendor_qcomsysd vendor_sysfs_soc:file w_file_perms;
allow vendor_qcomsysd self:socket create;
allow vendor_qcomsysd self:capability { sys_boot };
allow vendor_qcomsysd self:capability { sys_boot kill };
allow vendor_qcomsysd self:qipcrtr_socket create_socket_perms_no_ioctl;
use_vendor_per_mgr(vendor_qcomsysd);
#allow qcomsysd access boot mode switch