Add hal_bootctl related policy am: bab5b72f86

Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/21508207

Change-Id: Ic3ea1d971850ee209d9cfc61ba448ff62bbde5f5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
This commit is contained in:
Wilson Sung 2023-02-21 23:04:44 +00:00 committed by Automerger Merge Worker
commit 393e31b676
3 changed files with 2 additions and 5 deletions

View file

@ -9,7 +9,6 @@ google_camera_app audio_service service_manager b/264600171
google_camera_app backup_service service_manager b/264483456 google_camera_app backup_service service_manager b/264483456
google_camera_app legacy_permission_service service_manager b/264600171 google_camera_app legacy_permission_service service_manager b/264600171
google_camera_app permission_checker_service service_manager b/264600171 google_camera_app permission_checker_service service_manager b/264600171
hal_bootctl_default devinfo_block_device blk_file b/264483787
hal_camera_default hal_radioext_hwservice hwservice_manager b/264483024 hal_camera_default hal_radioext_hwservice hwservice_manager b/264483024
hal_dumpstate_default vendor_displaycolor_service service_manager b/264482983 hal_dumpstate_default vendor_displaycolor_service service_manager b/264482983
hal_dumpstate_default vendor_displaycolor_service service_manager b/264600086 hal_dumpstate_default vendor_displaycolor_service service_manager b/264600086

View file

@ -1,7 +1,3 @@
# b/264489609
userdebug_or_eng(`
permissive hal_bootctl_default;
')
# b/267843310 # b/267843310
dontaudit hal_bootctl_default hal_bootctl_default:capability { dac_override }; dontaudit hal_bootctl_default hal_bootctl_default:capability { dac_override };
dontaudit hal_bootctl_default tee_device:chr_file { ioctl }; dontaudit hal_bootctl_default tee_device:chr_file { ioctl };

View file

@ -1 +1,3 @@
allow hal_bootctl_default devinfo_block_device:blk_file r_file_perms; allow hal_bootctl_default devinfo_block_device:blk_file r_file_perms;
allow hal_bootctl_default sda_block_device:blk_file rw_file_perms;
allow hal_bootctl_default sysfs_ota:file rw_file_perms;