Fix selinux error for aocd

allow write permission to fix following error
auditd  : type=1400 audit(0.0:4): avc: denied { write } for comm="aocd" name="aoc" dev="tmpfs" ino=497 scontext=u:r:aocd:s0 tcontext=u:object_r:aoc_device:s0 tclass=chr_file permissive=0

Bug: 198490099
Test: no avc deny when enable no_ap_restart
Change-Id: I06dc99f1a5859589b33f89ce435745d15e2e5749
Signed-off-by: Robert Lee <lerobert@google.com>
This commit is contained in:
Robert Lee 2022-03-02 14:45:47 +08:00
parent 2d43200489
commit 129ef29bc8

View file

@ -12,7 +12,7 @@ allow aocd sysfs_aoc:dir search;
allow aocd sysfs_aoc_firmware:file w_file_perms; allow aocd sysfs_aoc_firmware:file w_file_perms;
# dev operations # dev operations
allow aocd aoc_device:chr_file r_file_perms; allow aocd aoc_device:chr_file rw_file_perms;
# allow inotify to watch for additions/removals from /dev # allow inotify to watch for additions/removals from /dev
allow aocd device:dir r_dir_perms; allow aocd device:dir r_dir_perms;