Grant citadeld access

Test: boot to home under enforcing mode
Bug: 205657177
Bug: 205904322
Change-Id: I49a7f14d4948f94814067e7ef137186610547033
This commit is contained in:
Adam Shih 2022-01-03 10:36:37 +08:00 committed by TreeHugger Robot
parent 7fe7e43582
commit b627a2f18b
2 changed files with 2 additions and 12 deletions

View file

@ -5,6 +5,8 @@ init_daemon_domain(citadeld)
add_service(citadeld, citadeld_service) add_service(citadeld, citadeld_service)
binder_use(citadeld) binder_use(citadeld)
vndbinder_use(citadeld)
allow citadeld citadel_device:chr_file rw_file_perms;
allow citadeld fwk_stats_service:service_manager find; allow citadeld fwk_stats_service:service_manager find;
allow citadeld hal_power_stats_vendor_service:service_manager find; allow citadeld hal_power_stats_vendor_service:service_manager find;

View file

@ -1,14 +1,2 @@
# b/205657177
dontaudit citadeld citadel_device:chr_file { getattr };
dontaudit citadeld citadel_device:chr_file { ioctl };
dontaudit citadeld citadel_device:chr_file { open };
dontaudit citadeld citadel_device:chr_file { read write };
dontaudit citadeld vndbinder_device:chr_file { ioctl };
dontaudit citadeld vndbinder_device:chr_file { map };
dontaudit citadeld vndbinder_device:chr_file { open };
dontaudit citadeld vndbinder_device:chr_file { read };
dontaudit citadeld vndbinder_device:chr_file { write };
# b/205904322 # b/205904322
dontaudit citadeld system_server:binder { call }; dontaudit citadeld system_server:binder { call };
dontaudit citadeld vndservicemanager:binder { call };
dontaudit citadeld vndservicemanager:binder { transfer };