Merge "display: add sepolicy for hal_graphics_composer" into sc-dev
This commit is contained in:
commit
96d0c28dc4
3 changed files with 5 additions and 23 deletions
|
@ -32,3 +32,7 @@ add_service(hal_graphics_composer_default, vendor_displaycolor_service)
|
||||||
|
|
||||||
add_service(hal_graphics_composer_default, hal_pixel_display_service)
|
add_service(hal_graphics_composer_default, hal_pixel_display_service)
|
||||||
binder_use(hal_graphics_composer_default)
|
binder_use(hal_graphics_composer_default)
|
||||||
|
get_prop(hal_graphics_composer_default, boot_status_prop);
|
||||||
|
|
||||||
|
# allow HWC to access vendor log file
|
||||||
|
allow hal_graphics_composer_default vendor_log_file:file create_file_perms;
|
||||||
|
|
|
@ -1,23 +0,0 @@
|
||||||
# b/181712799
|
|
||||||
dontaudit hal_graphics_composer_default hal_power_default:binder { call };
|
|
||||||
dontaudit hal_graphics_composer_default boot_status_prop:file { read };
|
|
||||||
dontaudit hal_graphics_composer_default boot_status_prop:file { open };
|
|
||||||
dontaudit hal_graphics_composer_default boot_status_prop:file { getattr };
|
|
||||||
dontaudit hal_graphics_composer_default boot_status_prop:file { map };
|
|
||||||
dontaudit hal_graphics_composer_default hal_power_default:binder { call };
|
|
||||||
dontaudit hal_graphics_composer_default boot_status_prop:file { map };
|
|
||||||
dontaudit hal_graphics_composer_default vendor_log_file:file { create };
|
|
||||||
dontaudit hal_graphics_composer_default vendor_log_file:file { append open };
|
|
||||||
dontaudit hal_graphics_composer_default vendor_log_file:file { getattr };
|
|
||||||
dontaudit hal_graphics_composer_default vendor_log_file:file { getattr };
|
|
||||||
dontaudit hal_graphics_composer_default vendor_log_file:file { append open };
|
|
||||||
dontaudit hal_graphics_composer_default vendor_log_file:file { create };
|
|
||||||
dontaudit hal_graphics_composer_default hal_power_service:service_manager { find };
|
|
||||||
dontaudit hal_graphics_composer_default boot_status_prop:file { read };
|
|
||||||
dontaudit hal_graphics_composer_default boot_status_prop:file { open };
|
|
||||||
dontaudit hal_graphics_composer_default boot_status_prop:file { getattr };
|
|
||||||
# b/181915065
|
|
||||||
dontaudit hal_graphics_composer_default hal_dumpstate_default:fd { use };
|
|
||||||
dontaudit hal_graphics_composer_default hal_dumpstate_default:fifo_file { write };
|
|
||||||
dontaudit hal_graphics_composer_default hal_dumpstate_default:fd { use };
|
|
||||||
dontaudit hal_graphics_composer_default hal_dumpstate_default:fifo_file { write };
|
|
|
@ -3,3 +3,4 @@ allow hal_graphics_composer_default sysfs_display:file rw_file_perms;
|
||||||
|
|
||||||
# allow HWC to access power hal
|
# allow HWC to access power hal
|
||||||
binder_call(hal_graphics_composer_default, hal_power_default);
|
binder_call(hal_graphics_composer_default, hal_power_default);
|
||||||
|
hal_client_domain(hal_graphics_composer_default, hal_power);
|
||||||
|
|
Loading…
Add table
Add a link
Reference in a new issue