Merge "Add vendor_misc_writer." am: ccf8af80b0
am: 986d2b296a
am: 848861d8a3
Change-Id: I06594eada403a2634d7e8b5984071c664371eb6e
This commit is contained in:
commit
c576c2c835
5 changed files with 16 additions and 0 deletions
|
@ -144,6 +144,8 @@
|
||||||
vendor_idc_file
|
vendor_idc_file
|
||||||
vendor_keychars_file
|
vendor_keychars_file
|
||||||
vendor_keylayout_file
|
vendor_keylayout_file
|
||||||
|
vendor_misc_writer
|
||||||
|
vendor_misc_writer_exec
|
||||||
vendor_task_profiles_file
|
vendor_task_profiles_file
|
||||||
vrflinger_vsync_service
|
vrflinger_vsync_service
|
||||||
watchdogd_tmpfs))
|
watchdogd_tmpfs))
|
||||||
|
|
|
@ -351,6 +351,7 @@
|
||||||
/(vendor|system/vendor)/framework(/.*)? u:object_r:vendor_framework_file:s0
|
/(vendor|system/vendor)/framework(/.*)? u:object_r:vendor_framework_file:s0
|
||||||
|
|
||||||
/vendor/apex(/[^/]+){0,2} u:object_r:vendor_apex_file:s0
|
/vendor/apex(/[^/]+){0,2} u:object_r:vendor_apex_file:s0
|
||||||
|
/vendor/bin/misc_writer u:object_r:vendor_misc_writer_exec:s0
|
||||||
|
|
||||||
# HAL location
|
# HAL location
|
||||||
/(vendor|system/vendor)/lib(64)?/hw u:object_r:vendor_hal_file:s0
|
/(vendor|system/vendor)/lib(64)?/hw u:object_r:vendor_hal_file:s0
|
||||||
|
|
|
@ -603,6 +603,7 @@ neverallow {
|
||||||
-uncrypt
|
-uncrypt
|
||||||
-update_engine
|
-update_engine
|
||||||
-vendor_init
|
-vendor_init
|
||||||
|
-vendor_misc_writer
|
||||||
-vold
|
-vold
|
||||||
-recovery
|
-recovery
|
||||||
-ueventd
|
-ueventd
|
||||||
|
|
11
public/vendor_misc_writer.te
Normal file
11
public/vendor_misc_writer.te
Normal file
|
@ -0,0 +1,11 @@
|
||||||
|
# vendor_misc_writer
|
||||||
|
type vendor_misc_writer, domain;
|
||||||
|
type vendor_misc_writer_exec, vendor_file_type, exec_type, file_type;
|
||||||
|
|
||||||
|
# Raw writes to misc_block_device
|
||||||
|
allow vendor_misc_writer misc_block_device:blk_file w_file_perms;
|
||||||
|
allow vendor_misc_writer block_device:dir r_dir_perms;
|
||||||
|
|
||||||
|
# Silence the denial when calling libfstab's ReadDefaultFstab.
|
||||||
|
dontaudit vendor_misc_writer proc_cmdline:file read;
|
||||||
|
dontaudit vendor_misc_writer metadata_file:dir search;
|
1
vendor/vendor_misc_writer.te
vendored
Normal file
1
vendor/vendor_misc_writer.te
vendored
Normal file
|
@ -0,0 +1 @@
|
||||||
|
init_daemon_domain(vendor_misc_writer)
|
Loading…
Reference in a new issue