platform_vendor_tequila/sepolicy/vold.te
LuK1337 314a2bc163 sepolicy: Allow vold to getattr on mkfs_exec
* Fixes denial while trying to format external
  SDcard as adopted storage.

Change-Id: I244ec9b5886888e1cbe488c671b9862b653f73a9
2016-09-18 09:02:08 -07:00

23 lines
728 B
Text

domain_trans(init, rootfs, vold)
# Allow vold to manage ASEC
allow vold sdcard_type:file create_file_perms;
allow vold vold_tmpfs:file create_file_perms;
# Allow vold to access fuse for fuse-based fs
allow vold fuseblk:chr_file rw_file_perms;
# NTFS-3g wants to drop permission
allow vold self:capability { setgid setuid };
# Vold can also run as minivold in the rootfs
recovery_only(`
allow vold rootfs:dir { add_name write };
allow vold rootfs:file execute_no_trans;
allow vold vold_tmpfs:file link;
')
# External storage
allow vold storage_stub_file:dir { rw_file_perms search add_name };
allow vold mnt_media_rw_stub_file:dir r_dir_perms;
allow vold mkfs_exec:file { execute read open getattr execute_no_trans };