From b46b936df8f77905f15d47f3a4e5e51b21d0d849 Mon Sep 17 00:00:00 2001 From: Mike McTernan Date: Tue, 4 Apr 2023 22:59:45 +0100 Subject: [PATCH] confirmationui: Allow securedpud to access the systemsuspend HAL. In order to use a wakelock, securedpud needs access to binder and the system_suspend_service HAL. Bug: 274851247 Test: manual, trigger TUI and check for AVC denials Change-Id: Ibd27d32e092269f91d6557ebddcd27d4ccf1355a --- confirmationui/securedpud.slider.te | 2 ++ 1 file changed, 2 insertions(+) diff --git a/confirmationui/securedpud.slider.te b/confirmationui/securedpud.slider.te index fd553a30..e0d272f1 100644 --- a/confirmationui/securedpud.slider.te +++ b/confirmationui/securedpud.slider.te @@ -3,6 +3,8 @@ type securedpud_slider_exec, exec_type, vendor_file_type, file_type; init_daemon_domain(securedpud_slider) +wakelock_use(securedpud_slider) + allow securedpud_slider dmabuf_heap_device:chr_file r_file_perms; allow securedpud_slider ion_device:chr_file r_file_perms; allow securedpud_slider tee_device:chr_file rw_file_perms;