diff --git a/tracking_denials/hal_bootctl_default.te b/tracking_denials/hal_bootctl_default.te deleted file mode 100644 index 27271c57..00000000 --- a/tracking_denials/hal_bootctl_default.te +++ /dev/null @@ -1,3 +0,0 @@ -# b/182705986 -dontaudit hal_bootctl_default devinfo_block_device:blk_file { open }; -dontaudit hal_bootctl_default devinfo_block_device:blk_file { read }; diff --git a/whitechapel/vendor/google/hal_bootctl_default.te b/whitechapel/vendor/google/hal_bootctl_default.te index 63741aed..fd5063f9 100644 --- a/whitechapel/vendor/google/hal_bootctl_default.te +++ b/whitechapel/vendor/google/hal_bootctl_default.te @@ -1 +1,2 @@ allow hal_bootctl_default sda_block_device:blk_file rw_file_perms; +allow hal_bootctl_default devinfo_block_device:blk_file r_file_perms;