Merge "Use label persist_ss_file" into sc-dev am: 6550281b13

Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14987305

Change-Id: I7cfd671dd52f5422b317a6cd2f12847f65ee9a13
This commit is contained in:
TreeHugger Robot 2021-06-16 06:04:10 +00:00 committed by Automerger Merge Worker
commit a0e1a8e2e4
2 changed files with 2 additions and 1 deletions

View file

@ -335,7 +335,7 @@
/vendor/bin/hw/android\.hardware\.confirmationui@1\.0-service\.trusty\.vendor u:object_r:hal_confirmationui_default_exec:s0 /vendor/bin/hw/android\.hardware\.confirmationui@1\.0-service\.trusty\.vendor u:object_r:hal_confirmationui_default_exec:s0
/dev/trusty-ipc-dev0 u:object_r:tee_device:s0 /dev/trusty-ipc-dev0 u:object_r:tee_device:s0
/data/vendor/ss(/.*)? u:object_r:tee_data_file:s0 /data/vendor/ss(/.*)? u:object_r:tee_data_file:s0
/mnt/vendor/persist/ss(/.*)? u:object_r:tee_data_file:s0 /mnt/vendor/persist/ss(/.*)? u:object_r:persist_ss_file:s0
/dev/sg1 u:object_r:sg_device:s0 /dev/sg1 u:object_r:sg_device:s0
/dev/trusty-log0 u:object_r:logbuffer_device:s0 /dev/trusty-log0 u:object_r:logbuffer_device:s0

View file

@ -1,6 +1,7 @@
type sg_device, dev_type; type sg_device, dev_type;
type persist_ss_file, file_type, vendor_persist_type; type persist_ss_file, file_type, vendor_persist_type;
allow tee persist_ss_file:file rw_file_perms;
allow tee persist_ss_file:dir r_dir_perms; allow tee persist_ss_file:dir r_dir_perms;
allow tee persist_file:dir r_dir_perms; allow tee persist_file:dir r_dir_perms;
allow tee mnt_vendor_file:dir r_dir_perms; allow tee mnt_vendor_file:dir r_dir_perms;