Merge "CastAuth: SELinux rules for the MediaDrm plugin" into tm-qpr-dev
This commit is contained in:
commit
bf74335744
4 changed files with 19 additions and 0 deletions
3
vendor/file.te
vendored
3
vendor/file.te
vendored
|
@ -1,2 +1,5 @@
|
||||||
#Pogo USB control & status
|
#Pogo USB control & status
|
||||||
type sysfs_pogo_usb, sysfs_type, fs_type;
|
type sysfs_pogo_usb, sysfs_type, fs_type;
|
||||||
|
|
||||||
|
# Cast device certificate
|
||||||
|
type device_cert_file, file_type, vendor_persist_type;
|
||||||
|
|
4
vendor/file_contexts
vendored
4
vendor/file_contexts
vendored
|
@ -9,3 +9,7 @@
|
||||||
|
|
||||||
# Privacy LED
|
# Privacy LED
|
||||||
/vendor/bin/hw/android\.hardware\.lights-service\.tangorpro u:object_r:hal_light_default_exec:s0
|
/vendor/bin/hw/android\.hardware\.lights-service\.tangorpro u:object_r:hal_light_default_exec:s0
|
||||||
|
|
||||||
|
# Cast Factory Credentials
|
||||||
|
/vendor/bin/hw/android\.hardware\.drm-service\.castkey u:object_r:hal_drm_cast_exec:s0
|
||||||
|
/mnt/vendor/persist/nest/cast_auth\.crt u:object_r:device_cert_file:s0
|
||||||
|
|
10
vendor/hal_drm_cast.te
vendored
Normal file
10
vendor/hal_drm_cast.te
vendored
Normal file
|
@ -0,0 +1,10 @@
|
||||||
|
type hal_drm_cast, domain;
|
||||||
|
type hal_drm_cast_exec, exec_type, vendor_file_type, file_type;
|
||||||
|
|
||||||
|
init_daemon_domain(hal_drm_cast)
|
||||||
|
hal_server_domain(hal_drm_cast, hal_drm)
|
||||||
|
|
||||||
|
allow hal_drm_cast mnt_vendor_file:dir search;
|
||||||
|
allow hal_drm_cast persist_file:dir search;
|
||||||
|
allow hal_drm_cast device_cert_file:file r_file_perms;
|
||||||
|
neverallow { domain -init -vendor_init -hal_drm_cast } device_cert_file:file no_rw_file_perms;
|
2
vendor/service_contexts
vendored
Normal file
2
vendor/service_contexts
vendored
Normal file
|
@ -0,0 +1,2 @@
|
||||||
|
# Cast Factory Credentials
|
||||||
|
android.hardware.drm.IDrmFactory/castkey u:object_r:hal_drm_service:s0
|
Loading…
Add table
Add a link
Reference in a new issue