From 129ef29bc8f2c3524de13a9b2e9d8e22d5da4d77 Mon Sep 17 00:00:00 2001 From: Robert Lee Date: Wed, 2 Mar 2022 14:45:47 +0800 Subject: [PATCH] Fix selinux error for aocd allow write permission to fix following error auditd : type=1400 audit(0.0:4): avc: denied { write } for comm="aocd" name="aoc" dev="tmpfs" ino=497 scontext=u:r:aocd:s0 tcontext=u:object_r:aoc_device:s0 tclass=chr_file permissive=0 Bug: 198490099 Test: no avc deny when enable no_ap_restart Change-Id: I06dc99f1a5859589b33f89ce435745d15e2e5749 Signed-off-by: Robert Lee --- aoc/aocd.te | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/aoc/aocd.te b/aoc/aocd.te index 79add165..69b0af0d 100644 --- a/aoc/aocd.te +++ b/aoc/aocd.te @@ -12,7 +12,7 @@ allow aocd sysfs_aoc:dir search; allow aocd sysfs_aoc_firmware:file w_file_perms; # dev operations -allow aocd aoc_device:chr_file r_file_perms; +allow aocd aoc_device:chr_file rw_file_perms; # allow inotify to watch for additions/removals from /dev allow aocd device:dir r_dir_perms;