From 0ea531896c972580493d998e57ee701820c43042 Mon Sep 17 00:00:00 2001 From: Kris Chen Date: Tue, 21 Mar 2023 19:24:32 +0800 Subject: [PATCH] Allow fingerprint hal to read sysfs_leds Fix the following avc denials: avc: denied { search } for name="backlight" dev="sysfs" ino=79316 scontext=u:r:hal_fingerprint_default:s0 tcontext=u:object_r:sysfs_leds:s0 tclass=dir permissive=1 avc: denied { read } for name="state" dev="sysfs" ino=79365 scontext=u:r:hal_fingerprint_default:s0 tcontext=u:object_r:sysfs_leds:s0 tclass=file permissive=1 Bug: 271072126 Test: Authenticate fingerprint. Change-Id: Ibefbcefc005ab2cec7c417f197fd134b154ed9a1 --- vendor/hal_fingerprint_default.te | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/vendor/hal_fingerprint_default.te b/vendor/hal_fingerprint_default.te index 28f372c1..6aa57dde 100644 --- a/vendor/hal_fingerprint_default.te +++ b/vendor/hal_fingerprint_default.te @@ -33,3 +33,7 @@ binder_call(hal_fingerprint_default, hal_graphics_composer_default) # allow fingerprint to access thermal hal hal_client_domain(hal_fingerprint_default, hal_thermal); + +# allow fingerprint to read sysfs_leds +allow hal_fingerprint_default sysfs_leds:file r_file_perms; +allow hal_fingerprint_default sysfs_leds:dir r_dir_perms;