platform_system_sepolicy/prebuilts/api/31.0/private/lmkd.te
Suren Baghdasaryan 88b6d77592 sepolicy: Allow lmkd to access bpf map to read GPU allocation statistics
Lmkd needs read access to /sys/fs/bpf/map_gpu_mem_gpu_mem_total_map BPF
map to obtain information on GPU memory allocations.

Bug: 189366037
Test: lmkd_unit_test
Signed-off-by: Suren Baghdasaryan <surenb@google.com>
Change-Id: I59ded4bc5ec97861e50b4fd1fdd6efb23990b79c
Merged-In: I59ded4bc5ec97861e50b4fd1fdd6efb23990b79c
2021-06-16 15:53:56 +00:00

15 lines
345 B
Text

typeattribute lmkd coredomain;
init_daemon_domain(lmkd)
# Set sys.lmk.* properties.
set_prop(lmkd, system_lmk_prop)
# Set lmkd.* properties.
set_prop(lmkd, lmkd_prop)
allow lmkd fs_bpf:dir search;
allow lmkd fs_bpf:file read;
allow lmkd bpfloader:bpf map_read;
neverallow { domain -init -lmkd -vendor_init } lmkd_prop:property_service set;