sm6150-common: sepolicy: Add sepolicy for kernel to access /data/per_boot/zram_swap
type=1400 audit(1581485243.256:88): avc: denied { read } for comm="loop29" path="/data/per_boot/zram_swap" dev="dm-9" ino=9820 scontext=u:r:kernel:s0 tcontext=u:object_r:system_data_file:s0 tclass=file permissive=0 Bug: 147469156 Test: flash full build and find avc errors gone Change-Id: I48d7684ce3b4ca1ada81011b1cab21007c758ba5 Signed-off-by: Mimi Wu <mimiwu@google.com>
This commit is contained in:
parent
8a938dd6e1
commit
73025604d6
2
sepolicy/vendor/file.te
vendored
Normal file
2
sepolicy/vendor/file.te
vendored
Normal file
@ -0,0 +1,2 @@
|
||||
# Data files
|
||||
type per_boot_file, file_type, data_file_type, core_data_file_type;
|
3
sepolicy/vendor/file_contexts
vendored
3
sepolicy/vendor/file_contexts
vendored
@ -4,6 +4,9 @@
|
||||
# Camera
|
||||
/mnt/vendor/persist/camera(/.*)? u:object_r:camera_persist_file:s0
|
||||
|
||||
# Data files
|
||||
/data/per_boot(/.*)? u:object_r:per_boot_file:s0
|
||||
|
||||
# Display
|
||||
/dev/xiaomi-touch u:object_r:touchfeature_device:s0
|
||||
/sys/devices/platform/soc/[a-f0-9]+.qcom,mdss_mdp/drm/card([0-3])+/card([0-3])+-DSI-1/panel_info u:object_r:vendor_sysfs_graphics:s0
|
||||
|
1
sepolicy/vendor/kernel.te
vendored
Normal file
1
sepolicy/vendor/kernel.te
vendored
Normal file
@ -0,0 +1 @@
|
||||
allow kernel per_boot_file:file r_file_perms;
|
Loading…
Reference in New Issue
Block a user