diff --git a/tracking_denials/rfsd.te b/tracking_denials/rfsd.te deleted file mode 100644 index bf921ff4..00000000 --- a/tracking_denials/rfsd.te +++ /dev/null @@ -1,3 +0,0 @@ -# b/205904361 -dontaudit rfsd rfsd:capability { chown }; -dontaudit rfsd rfsd:capability { setuid }; diff --git a/whitechapel_pro/rfsd.te b/whitechapel_pro/rfsd.te index 898e7fca..2d1f0928 100644 --- a/whitechapel_pro/rfsd.te +++ b/whitechapel_pro/rfsd.te @@ -2,6 +2,9 @@ type rfsd, domain; type rfsd_exec, vendor_file_type, exec_type, file_type; init_daemon_domain(rfsd) +# Allow to setuid from root to radio and chown of modem efs files +allow rfsd self:capability { chown setuid }; + # Allow to search block device and mnt dir for modem EFS partitions allow rfsd mnt_vendor_file:dir search; allow rfsd block_device:dir search;