[ 33.709752][ T363] type=1400 audit(1725519791.892:729): avc: denied { read } for comm="binder:369_6" name="/" dev="sda5" ino=3 scontext=u:r:vold:s0 tcontext=u:object_r:modem_efs_file:s0 tclass=dir permissive=1 [ 33.710804][ T363] type=1400 audit(1725519791.892:730): avc: denied { open } for comm="binder:369_6" path="/mnt/vendor/efs" dev="sda5" ino=3 scontext=u:r:vold:s0 tcontext=u:object_r:modem_efs_file:s0 tclass=dir permissive=1 [ 33.711734][ T363] type=1400 audit(1725519791.892:731): avc: denied { ioctl } for comm="binder:369_6" path="/mnt/vendor/efs" dev="sda5" ino=3 ioctlcmd=0x5879 scontext=u:r:vold:s0 tcontext=u:object_r:modem_efs_file:s0 tclass=dir permissive=1 [ 33.712732][ T363] type=1400 audit(1725519791.892:732): avc: denied { read } for comm="binder:369_6" name="/" dev="sda7" ino=3 scontext=u:r:vold:s0 tcontext=u:object_r:modem_userdata_file:s0 tclass=dir permissive=1 [ 33.713612][ T363] type=1400 audit(1725519791.892:733): avc: denied { open } for comm="binder:369_6" path="/mnt/vendor/modem_userdata" dev="sda7" ino=3 scontext=u:r:vold:s0 tcontext=u:object_r:modem_userdata_file:s0 tclass=dir permissive=1 [ 33.714833][ T363] type=1400 audit(1725519791.892:734): avc: denied { ioctl } for comm="binder:369_6" path="/mnt/vendor/modem_userdata" dev="sda7" ino=3 ioctlcmd=0x5879 scontext=u:r:vold:s0 tcontext=u:object_r:modem_userdata_file:s0 tclass=dir permissive=1 Bug: 361093041 Test: local build Change-Id: I629f0303940f3f07ce3717cd0a2c8f975378f24b Signed-off-by: Randall Huang <huangrandall@google.com>
17 lines
574 B
Text
17 lines
574 B
Text
# ufs hagc
|
|
allow vold sysfs_scsi_devices_0000:file rw_file_perms;
|
|
|
|
# Access userdata_exp block device.
|
|
allow vold userdata_exp_block_device:blk_file rw_file_perms;
|
|
allowxperm vold userdata_exp_block_device:blk_file ioctl BLKSECDISCARD;
|
|
|
|
# adb bugreport
|
|
dontaudit vold dumpstate:fifo_file rw_file_perms;
|
|
dontaudit vold dumpstate:fd use ;
|
|
|
|
# fix idle-maint
|
|
allow vold efs_block_device:blk_file { getattr };
|
|
allow vold modem_userdata_block_device:blk_file { getattr };
|
|
allow vold modem_efs_file:dir { read open ioctl };
|
|
allow vold modem_userdata_file:dir { read open ioctl };
|
|
|