From 68849437bdfcdebe6b02d8d7d7ecb3ec09ab9614 Mon Sep 17 00:00:00 2001 From: Vinay Kalia Date: Mon, 24 May 2021 23:54:17 +0000 Subject: [PATCH] Allow mediacodec to access the vframe-secure DMA-BUF heap This patch fixes the following denial: HwBinder:751_2: type=1400 audit(0.0:9): avc: denied { open } for path="/dev/dma_heap/vframe-secure" dev="tmpfs" ino=734 scontext=u:r:mediacodec:s0 tcontext=u:object_r:vframe_heap_device:s0 tclass=chr_file permissive=0 Bug: 188121584 Test: AV1 secure video playback Signed-off-by: Vinay Kalia Change-Id: I455b39914dd4316a427f5f756b4fb94a2c4db204 --- whitechapel/vendor/google/mediacodec.te | 1 + 1 file changed, 1 insertion(+) diff --git a/whitechapel/vendor/google/mediacodec.te b/whitechapel/vendor/google/mediacodec.te index ed7c1adf..07a0a5b4 100644 --- a/whitechapel/vendor/google/mediacodec.te +++ b/whitechapel/vendor/google/mediacodec.te @@ -7,3 +7,4 @@ allow mediacodec hal_camera_default:binder call; allow mediacodec sysfs_video:file r_file_perms; allow mediacodec sysfs_video:dir r_dir_perms; allow mediacodec dmabuf_system_secure_heap_device:chr_file r_file_perms; +allow mediacodec vframe_heap_device:chr_file r_file_perms;