servicemanager: allow to read VINTF files in recovery.

Test: manual
Bug: 206888109
Change-Id: I2b7f0f33c27beb0d4401d1d697fdc58e7c62986f
This commit is contained in:
Yifan Hong 2021-12-07 14:31:04 -08:00
parent d725f8acaf
commit 259491ba0b

View file

@ -31,7 +31,10 @@ allow servicemanager dumpstate:fifo_file write;
# Check SELinux permissions.
selinux_check_access(servicemanager)
# In recovery, log to kmsg.
recovery_only(`
# In recovery, log to kmsg.
allow servicemanager kmsg_device:chr_file rw_file_perms;
# Read VINTF files.
r_dir_file(servicemanager, rootfs)
')