[Detail] There is a workaround for bring-up, now it needs to be modified. [Solution] 1.Split workaround to sepcial *.te 2.Modify ged sepolicy 3.Modify mistake 4.Add sepolicy MTK-Commit-Id: 5a2b7e3fdc826a7ca6bc70a3810f14c1661e7d79 Change-Id: I0894de45e014a5eae754e35b57fbc9b21bc4bf90 CR-Id: ALPS04639771 Feature: [Android Default] SELinux, SEAndroid, and SE-MTK
54 lines
2.1 KiB
Plaintext
54 lines
2.1 KiB
Plaintext
vndbinder_use(hal_graphics_composer_default)
|
|
|
|
allow hal_graphics_composer_default debugfs_ged:dir search;
|
|
|
|
# Date : WK17.09
|
|
# Operation : Add sepolicy
|
|
# Purpose : Add polivy for hwc HIDL
|
|
|
|
allow hal_graphics_composer_default proc:file { read getattr open ioctl };
|
|
allow hal_graphics_composer_default proc_ged:file r_file_perms;
|
|
allow hal_graphics_composer_default self:netlink_kobject_uevent_socket { read bind create setopt };
|
|
|
|
# Date : WK17.21
|
|
# Purpose: GPU driver required
|
|
allow hal_graphics_composer_default sw_sync_device:chr_file { read write open ioctl };
|
|
allow hal_graphics_composer_default hal_graphics_mapper_hwservice:hwservice_manager find;
|
|
|
|
# Date : W17.24
|
|
# Purpose: GPU driver required
|
|
allow hal_graphics_composer_default gpu_device:dir search;
|
|
|
|
allow hal_graphics_composer_default debugfs_ion:dir search;
|
|
allow hal_graphics_composer_default debugfs_tracing:file write;
|
|
allow hal_graphics_composer_default debugfs_tracing:file open;
|
|
|
|
# Date : WK17.30
|
|
# Operation : O Migration
|
|
# Purpose: Allow to access cmdq driver
|
|
allow hal_graphics_composer_default mtk_cmdq_device:chr_file { read ioctl open };
|
|
|
|
# Date : W17.30
|
|
# Add for control PowerHAL
|
|
allow hal_graphics_composer_default mtk_hal_power_hwservice:hwservice_manager find;
|
|
binder_call(hal_graphics_composer_default, mtk_hal_power)
|
|
|
|
# Date : WK17.32
|
|
# Operation : O Migration
|
|
# Purpose: Allow to access property
|
|
set_prop(hal_graphics_composer_default, graphics_hwc_pid_prop)
|
|
get_prop(hal_graphics_composer_default, graphics_hwc_pid_prop)
|
|
set_prop(hal_graphics_composer_default, graphics_hwc_latch_unsignaled_prop)
|
|
|
|
# Date : WK18.03
|
|
# Purpose: Allow to access property dev/mdp_sync
|
|
allow hal_graphics_composer_default mtk_mdp_device:chr_file { read write open ioctl };
|
|
allow hal_graphics_composer_default mdp_device:chr_file rw_file_perms;
|
|
allow hal_graphics_composer_default tee_device:chr_file rw_file_perms;
|
|
allowxperm hal_graphics_composer_default proc_ged:file ioctl { proc_ged_ioctls };
|
|
|
|
# Date: 2018/11/08
|
|
# Operation : JPEG
|
|
# Purpose : JPEG need to use PQ via MMS HIDL
|
|
allow hal_graphics_composer_default sysfs_boot_mode:file r_file_perms;
|