Merge "display: add sepolicy for hal_graphics_composer" into sc-dev

This commit is contained in:
TreeHugger Robot 2021-03-16 12:05:50 +00:00 committed by Android (Google) Code Review
commit 96d0c28dc4
3 changed files with 5 additions and 23 deletions

View file

@ -32,3 +32,7 @@ add_service(hal_graphics_composer_default, vendor_displaycolor_service)
add_service(hal_graphics_composer_default, hal_pixel_display_service) add_service(hal_graphics_composer_default, hal_pixel_display_service)
binder_use(hal_graphics_composer_default) binder_use(hal_graphics_composer_default)
get_prop(hal_graphics_composer_default, boot_status_prop);
# allow HWC to access vendor log file
allow hal_graphics_composer_default vendor_log_file:file create_file_perms;

View file

@ -1,23 +0,0 @@
# b/181712799
dontaudit hal_graphics_composer_default hal_power_default:binder { call };
dontaudit hal_graphics_composer_default boot_status_prop:file { read };
dontaudit hal_graphics_composer_default boot_status_prop:file { open };
dontaudit hal_graphics_composer_default boot_status_prop:file { getattr };
dontaudit hal_graphics_composer_default boot_status_prop:file { map };
dontaudit hal_graphics_composer_default hal_power_default:binder { call };
dontaudit hal_graphics_composer_default boot_status_prop:file { map };
dontaudit hal_graphics_composer_default vendor_log_file:file { create };
dontaudit hal_graphics_composer_default vendor_log_file:file { append open };
dontaudit hal_graphics_composer_default vendor_log_file:file { getattr };
dontaudit hal_graphics_composer_default vendor_log_file:file { getattr };
dontaudit hal_graphics_composer_default vendor_log_file:file { append open };
dontaudit hal_graphics_composer_default vendor_log_file:file { create };
dontaudit hal_graphics_composer_default hal_power_service:service_manager { find };
dontaudit hal_graphics_composer_default boot_status_prop:file { read };
dontaudit hal_graphics_composer_default boot_status_prop:file { open };
dontaudit hal_graphics_composer_default boot_status_prop:file { getattr };
# b/181915065
dontaudit hal_graphics_composer_default hal_dumpstate_default:fd { use };
dontaudit hal_graphics_composer_default hal_dumpstate_default:fifo_file { write };
dontaudit hal_graphics_composer_default hal_dumpstate_default:fd { use };
dontaudit hal_graphics_composer_default hal_dumpstate_default:fifo_file { write };

View file

@ -3,3 +3,4 @@ allow hal_graphics_composer_default sysfs_display:file rw_file_perms;
# allow HWC to access power hal # allow HWC to access power hal
binder_call(hal_graphics_composer_default, hal_power_default); binder_call(hal_graphics_composer_default, hal_power_default);
hal_client_domain(hal_graphics_composer_default, hal_power);