diff --git a/tracking_denials/cbd.te b/tracking_denials/cbd.te deleted file mode 100644 index 6527506e..00000000 --- a/tracking_denials/cbd.te +++ /dev/null @@ -1,4 +0,0 @@ -# b/205779872 -dontaudit cbd persist_file:dir { search }; -# b/205904432 -dontaudit cbd cbd:capability { setuid }; diff --git a/whitechapel_pro/cbd.te b/whitechapel_pro/cbd.te index 835a0e1c..c4cfe7a6 100644 --- a/whitechapel_pro/cbd.te +++ b/whitechapel_pro/cbd.te @@ -6,6 +6,9 @@ set_prop(cbd, vendor_modem_prop) set_prop(cbd, vendor_cbd_prop) set_prop(cbd, vendor_rild_prop) +# Allow cbd to set gid/uid from too to radio +allow cbd self:capability { setgid setuid }; + allow cbd mnt_vendor_file:dir r_dir_perms; allow cbd kmsg_device:chr_file rw_file_perms; @@ -27,6 +30,7 @@ allow cbd proc_cmdline:file r_file_perms; allow cbd persist_modem_file:dir create_dir_perms; allow cbd persist_modem_file:file create_file_perms; +allow cbd persist_file:dir search; allow cbd radio_vendor_data_file:dir create_dir_perms; allow cbd radio_vendor_data_file:file create_file_perms;