Bo Ye 5849c224e3 [ALPS03825066] P migration selinux build failed fix
1. Mark polices which accessing proc/sysfs file system
    2. Add violator attribute to modules violate vendor/system rule.

MTK-Commit-Id: 3954cad7a1428cda694d8428c2235a78aa6e7cc8

Change-Id: I401ae5b87eb9a03f324bef83c6678149606b15a8
CR-Id: ALPS03825066
Feature: [Android Default] SELinux, SEAndroid, and SE-MTK
2020-01-18 09:29:36 +08:00

45 lines
2.1 KiB
Plaintext

# ==============================================
# Policy File of /system/binstp_dump3 Executable File
# ==============================================
# Type Declaration
# ==============================================
type stp_dump3_exec , exec_type, file_type, vendor_file_type;
type stp_dump3 ,domain;
# ==============================================
# Android Policy Rule
# ==============================================
# ==============================================
# NSA Policy Rule
# ==============================================
# ==============================================
# MTK Policy Rule
# ==============================================
file_type_auto_trans(stp_dump3,system_data_file,stp_dump_data_file)
#allow stp_dump3 self:capability { net_admin fowner chown fsetid dac_override };
allow stp_dump3 self:netlink_socket { read write getattr bind create setopt };
allow stp_dump3 self:netlink_generic_socket { read write getattr bind create setopt };
#allow stp_dump3 media_rw_data_file:sock_file { write create unlink setattr };
typeattribute stp_dump3 data_between_core_and_vendor_violators;
allow stp_dump3 media_rw_data_file:dir { add_name setattr };
allow stp_dump3 media_rw_data_file:dir rmdir;
allow stp_dump3 media_rw_data_file:dir { open read write create setattr getattr add_name remove_name search};
allow stp_dump3 media_rw_data_file:file { open read write create setattr getattr append unlink rename};
allow stp_dump3 wmtdetect_device:chr_file { read write ioctl open };
allow stp_dump3 stpwmt_device:chr_file { read write ioctl open };
allow stp_dump3 tmpfs:lnk_file r_file_perms;
allow stp_dump3 tmpfs:lnk_file read;
allow stp_dump3 mnt_user_file:dir search;
allow stp_dump3 mnt_user_file:lnk_file read;
allow stp_dump3 storage_file:lnk_file read;
allow stp_dump3 sdcard_type:dir search;
allow stp_dump3 sdcard_type:dir {open read write create setattr getattr add_name remove_name search};
allow stp_dump3 sdcard_type:file { open read write create setattr getattr append unlink rename};
allow stp_dump3 sdcard_type:file create_file_perms;
init_daemon_domain(stp_dump3)