From 22b305228682bf42f779faccdd6ff2a88b7bed56 Mon Sep 17 00:00:00 2001 From: SamarV-121 Date: Mon, 12 Sep 2022 17:11:27 +0000 Subject: [PATCH] sepolicy: Allow init to create wfca_rds sockets I auditd : type=1400 audit(0.0:196): avc: denied { create } for comm="init" name="wfca_rds" scontext=u:r:init:s0 tcontext=u:object_r:socket_device:s0 tclass=sock_file permissive=0 Change-Id: I6205d0ac2e30e0558f1a1ba3b57283c433c8ac0b --- bsp/non_plat/init.te | 5 ++++- modem/file_contexts | 1 + 2 files changed, 5 insertions(+), 1 deletion(-) diff --git a/bsp/non_plat/init.te b/bsp/non_plat/init.te index 7a63da9..fd9585a 100644 --- a/bsp/non_plat/init.te +++ b/bsp/non_plat/init.te @@ -36,4 +36,7 @@ allow init proc_pressure_cpu:file setattr; # Date : W20.20 # Purpose: Allow to create socket for rild -allow init volte_imsvt1_socket:sock_file create_file_perms; +allow init { + volte_imsvt1_socket + wfca_socket +}:sock_file create_file_perms; diff --git a/modem/file_contexts b/modem/file_contexts index 45a97c8..8c75279 100644 --- a/modem/file_contexts +++ b/modem/file_contexts @@ -20,6 +20,7 @@ /dev/socket/volte_ua(/.*)? u:object_r:volte_ua_socket:s0 /dev/socket/volte_stack(/.*)? u:object_r:volte_stack_socket:s0 /dev/socket/wfca(/.*)? u:object_r:wfca_socket:s0 +/dev/socket/wfca_rds(/.*)? u:object_r:wfca_socket:s0 /dev/socket/bip(/.*)? u:object_r:bip_socket:s0 /dev/socket/vendor\.bip(/.*)? u:object_r:vendor_bip_socket:s0