d22987b4da
Motivation: Domain is overly permissive. Start removing permissions from domain and assign them to the domain_deprecated attribute. Domain_deprecated and domain can initially be assigned to all domains. The goal is to not assign domain_deprecated to new domains and to start removing domain_deprecated where it is not required or reassigning the appropriate permissions to the inheriting domain when necessary. Bug: 25433265 Change-Id: I8b11cb137df7bdd382629c98d916a73fe276413c
9 lines
332 B
Text
9 lines
332 B
Text
type hci_attach, domain, domain_deprecated;
|
|
type hci_attach_exec, exec_type, file_type;
|
|
|
|
init_daemon_domain(hci_attach)
|
|
|
|
allow hci_attach kernel:system module_request;
|
|
allow hci_attach hci_attach_dev:chr_file rw_file_perms;
|
|
allow hci_attach bluetooth_efs_file:dir r_dir_perms;
|
|
allow hci_attach bluetooth_efs_file:file r_file_perms;
|