diff --git a/non_plat/aee_aedv.te b/non_plat/aee_aedv.te index 61fd020..707e0c5 100644 --- a/non_plat/aee_aedv.te +++ b/non_plat/aee_aedv.te @@ -131,7 +131,7 @@ allow aee_aedv crash_dump:file r_file_perms; allow aee_aedv vendor_file:file execute_no_trans; # Purpose: debugfs files -allow aee_aedv debugfs:lnk_file read; +# allow aee_aedv debugfs:lnk_file read; allow aee_aedv debugfs_binder:dir { read open }; allow aee_aedv debugfs_binder:file { read open }; allow aee_aedv debugfs_blockio:file { read open }; diff --git a/non_plat/domain.te b/non_plat/domain.te index 3f509d7..14ceb2d 100644 --- a/non_plat/domain.te +++ b/non_plat/domain.te @@ -30,9 +30,9 @@ allow coredomain vendor_file:lnk_file { getattr read }; # Date:20170630 # Purpose: allow trusted process to connect aee daemon -allow { - coredomain - -untrusted_app_all -} aee_aed:unix_stream_socket connectto; +#allow { +# coredomain +# -untrusted_app_all +#} aee_aed:unix_stream_socket connectto; allow { domain -coredomain -hal_configstore_server -vendor_init } aee_aedv:unix_stream_socket connectto;