[Detail] Googles new commit
neverallow coredomain from writing vendor properties
cause build break
cdb1624c27
[Solution] Declare system_writes_vendor_properties_violators as workaround
MTK-Commit-Id: 2b19515d2d98945b0aadfbc9043352ae927497f3
Change-Id: I7be59b6811f6c75ea47da205be902417311fe1d0
CR-Id: ALPS03881723
Feature: [Android Default] SELinux, SEAndroid, and SE-MTK
67 lines
1.9 KiB
Plaintext
67 lines
1.9 KiB
Plaintext
# ==============================================
|
|
# MTK Policy Rule for vendor
|
|
# ==============================================
|
|
|
|
# Data : WK14.39
|
|
# Operation : Migration
|
|
# Purpose : dump for debug
|
|
typeattribute audioserver system_writes_vendor_properties_violators;
|
|
allow audioserver audiohal_prop:property_service set;
|
|
|
|
# Date: WK14.44
|
|
# Operation : Migration
|
|
# Purpose : EVDO
|
|
allow audioserver rpc_socket:sock_file write;
|
|
allow audioserver ttySDIO_device:chr_file rw_file_perms;
|
|
|
|
# Data: WK14.44
|
|
# Operation : Migration
|
|
# Purpose : for low SD card latency issue
|
|
allow audioserver sysfs_lowmemorykiller:file { read open };
|
|
|
|
# Data: WK14.45
|
|
# Operation : Migration
|
|
# Purpose : for change thermal policy when needed
|
|
allow audioserver proc_mtkcooler:dir search;
|
|
allow audioserver proc_mtktz:dir search;
|
|
allow audioserver proc_thermal:dir search;
|
|
|
|
# Date : WK15.03
|
|
# Operation : Migration
|
|
# Purpose : offloadservice
|
|
allow audioserver offloadservice_device:chr_file rw_file_perms;
|
|
|
|
# Date : WK16.17
|
|
# Operation : Migration
|
|
# Purpose: read/open sysfs node
|
|
allow audioserver sysfs_ccci:file r_file_perms;
|
|
|
|
# Date : WK16.18
|
|
# Operation : Migration
|
|
# Purpose: research root dir "/"
|
|
allow audioserver tmpfs:dir search;
|
|
|
|
# Date : WK16.18
|
|
# Operation : Migration
|
|
# Purpose: access sysfs node
|
|
#allow audioserver sysfs:file { open read write };
|
|
allow audioserver sysfs_ccci:dir search;
|
|
|
|
# Purpose: Dump debug info
|
|
allow audioserver debugfs_binder:dir search;
|
|
allow audioserver fuse:file write;
|
|
|
|
# Date : WK16.33
|
|
# Purpose: Allow to access ged for gralloc_extra functions
|
|
allow audioserver proc_ged:file {open read write ioctl getattr};
|
|
|
|
# Date : WK16.48
|
|
# Purpose: Allow to trigger AEE dump
|
|
allow audioserver aee_aed:unix_stream_socket connectto;
|
|
|
|
# Date : WK17.28
|
|
# Operation : MT6757 SQC
|
|
# Purpose : Change thermal config
|
|
allow audioserver mtk_thermal_config_prop:file { getattr open read };
|
|
allow audioserver mtk_thermal_config_prop:property_service set;
|