device_google_gs-common/storage/sepolicy/init.te
Jaegeuk Kim f329ce7a91 Fix selinux permission denials
[    9.280675] type=1400 audit(1737659534.344:11): avc:  denied  { mounton } for  comm="init" path="/data/vendor/intelligence" dev="dm-59" ino=490 scontext=u:r:init:s0 tcontext=u:object_r:intelligence_data_file:s0 tclass=dir permissive=0

Bug: 391452461
Flag: EXEMPT bugfix
Change-Id: I355c61bd2c5bb5af6d463cf84a3fc80093b16550
Signed-off-by: Jaegeuk Kim <jaegeuk@google.com>
2025-01-23 17:15:16 -08:00

4 lines
161 B
Text

# init
allow init sysfs_scsi_devices_0000:file w_file_perms;
allow init userdata_exp_block_device:blk_file write;
allow init intelligence_data_file:dir mounton;