Merge "[DO NOT MERGE] Add selinux policy for chre vendor data directory" into udc-qpr-dev

This commit is contained in:
Yixuan Wang 2023-08-23 19:29:45 +00:00 committed by Android (Google) Code Review
commit 0fcc802265
3 changed files with 6 additions and 0 deletions

4
vendor/chre.te vendored
View file

@ -9,6 +9,10 @@ allow chre aoc_device:chr_file rw_file_perms;
allow chre sysfs_aoc:dir search; allow chre sysfs_aoc:dir search;
allow chre sysfs_aoc_boottime:file r_file_perms; allow chre sysfs_aoc_boottime:file r_file_perms;
# Allow CHRE to write to data to chre data directory
allow chre chre_data_file:dir create_dir_perms;
allow chre chre_data_file:file create_file_perms;
# Allow CHRE to create thread to watch AOC's device # Allow CHRE to create thread to watch AOC's device
allow chre device:dir r_dir_perms; allow chre device:dir r_dir_perms;

1
vendor/file.te vendored
View file

@ -43,6 +43,7 @@ type vendor_bt_data_file, file_type, data_file_type;
type sensor_reg_data_file, file_type, data_file_type; type sensor_reg_data_file, file_type, data_file_type;
type uwb_vendor_data_file, file_type, data_file_type, app_data_file_type; type uwb_vendor_data_file, file_type, data_file_type, app_data_file_type;
type uwb_data_vendor, file_type, data_file_type; type uwb_data_vendor, file_type, data_file_type;
type chre_data_file, file_type, data_file_type;
# Vendor sched files # Vendor sched files
userdebug_or_eng(` userdebug_or_eng(`

View file

@ -44,6 +44,7 @@
# Vendor # Vendor
/data/vendor/bluetooth(/.*)? u:object_r:vendor_bt_data_file:s0 /data/vendor/bluetooth(/.*)? u:object_r:vendor_bt_data_file:s0
/data/vendor/uwb(/.*)? u:object_r:uwb_data_vendor:s0 /data/vendor/uwb(/.*)? u:object_r:uwb_data_vendor:s0
/data/vendor/chre(/.*)? u:object_r:chre_data_file:s0
# persist # persist
/mnt/vendor/persist/camera(/.*)? u:object_r:persist_camera_file:s0 /mnt/vendor/persist/camera(/.*)? u:object_r:persist_camera_file:s0