Robbin Chiu 734efb5717 [ALPS04763245] WMT: Fix sepolicy issue
[Solution]
Remove SEPolicy rules to fix
high risk sepolicy issues for stp_dump and wmt_loader

MTK-Commit-Id: 00ea2a4d222547ba0872c93521de79b8cb26673f

Change-Id: I8b31383f55f1075488a55c406ecd08bd5b3249af
Signed-off-by: Robbin Chiu <robbin.chiu@mediatek.com>
CR-Id: ALPS04763245
Feature: [Module]WMT Driver
2020-01-18 10:21:11 +08:00

44 lines
1.9 KiB
Plaintext

# ==============================================
# Policy File of /system/binstp_dump3 Executable File
# ==============================================
# Type Declaration
# ==============================================
type stp_dump3_exec, vendor_file_type, exec_type, file_type;
type stp_dump3, domain;
# ==============================================
# Android Policy Rule
# ==============================================
# ==============================================
# NSA Policy Rule
# ==============================================
# ==============================================
# MTK Policy Rule
# ==============================================
file_type_auto_trans(stp_dump3,vendor_data_file,stp_dump_data_file)
allow stp_dump3 self:capability { net_admin fowner chown fsetid };
allow stp_dump3 self:netlink_socket { read write getattr bind create setopt };
allow stp_dump3 self:netlink_generic_socket { read write getattr bind create setopt };
allow stp_dump3 wmtdetect_device:chr_file { read write ioctl open };
allow stp_dump3 stpwmt_device:chr_file rw_file_perms;
allow stp_dump3 tmpfs:lnk_file r_file_perms;
allow stp_dump3 tmpfs:lnk_file read;
allow stp_dump3 mnt_user_file:dir search;
allow stp_dump3 mnt_user_file:lnk_file read;
allow stp_dump3 storage_file:lnk_file read;
allow stp_dump3 sdcard_type:dir search;
allow stp_dump3 sdcard_type:dir {open read write create setattr getattr add_name remove_name search};
allow stp_dump3 sdcard_type:file { open read write create setattr getattr append unlink rename};
allow stp_dump3 sdcard_type:file create_file_perms;
allow stp_dump3 stp_dump_data_file:dir create_dir_perms;
allow stp_dump3 stp_dump_data_file:file create_file_perms;
allow stp_dump3 connsyslog_data_vendor_file:dir create_dir_perms;
allow stp_dump3 connsyslog_data_vendor_file:file create_file_perms;
get_prop(stp_dump3, coredump_prop)
init_daemon_domain(stp_dump3)