From 856d2c480e694ece9a24f75ca5d1e44f7da65d4c Mon Sep 17 00:00:00 2001 From: Wilson Sung Date: Wed, 8 Feb 2023 04:34:12 +0800 Subject: [PATCH] Allow kernel to access firmware and zram Bug: 260522245 Change-Id: I964ac1e30e0181f4d6edc71f2e066b7bd515186b --- tracking_denials/kernel.te | 6 +----- vendor/kernel.te | 5 +++++ 2 files changed, 6 insertions(+), 5 deletions(-) create mode 100644 vendor/kernel.te diff --git a/tracking_denials/kernel.te b/tracking_denials/kernel.te index afb73b96..315f001c 100644 --- a/tracking_denials/kernel.te +++ b/tracking_denials/kernel.te @@ -1,10 +1,6 @@ # b/260522245 -dontaudit kernel per_boot_file:file { read }; dontaudit kernel same_process_hal_file:file { open }; dontaudit kernel same_process_hal_file:file { read }; -dontaudit kernel vendor_fw_file:dir { search }; -dontaudit kernel vendor_fw_file:file { open }; -dontaudit kernel vendor_fw_file:file { read }; dontaudit kernel vendor_regmap_debugfs:dir { search }; # b/261650972 dontaudit kernel vendor_battery_debugfs:dir { search }; @@ -23,4 +19,4 @@ dontaudit kernel kernel:capability { net_bind_service }; # b/264490052 userdebug_or_eng(` permissive kernel; -') \ No newline at end of file +') diff --git a/vendor/kernel.te b/vendor/kernel.te new file mode 100644 index 00000000..cab39fb5 --- /dev/null +++ b/vendor/kernel.te @@ -0,0 +1,5 @@ +allow kernel vendor_fw_file:dir search; +allow kernel vendor_fw_file:file r_file_perms; + +# ZRam +allow kernel per_boot_file:file r_file_perms;