Merge "Add SE policies for HWC logs"

This commit is contained in:
TreeHugger Robot 2022-09-07 12:28:32 +00:00 committed by Android (Google) Code Review
commit 5a314cab17
4 changed files with 9 additions and 0 deletions

View file

@ -1,6 +1,7 @@
# Data # Data
type rild_vendor_data_file, file_type, data_file_type; type rild_vendor_data_file, file_type, data_file_type;
type vendor_log_file, file_type, data_file_type; type vendor_log_file, file_type, data_file_type;
type vendor_hwc_log_file, file_type, data_file_type;
type vendor_rfsd_log_file, file_type, data_file_type; type vendor_rfsd_log_file, file_type, data_file_type;
type modem_stat_data_file, file_type, data_file_type; type modem_stat_data_file, file_type, data_file_type;
type vendor_slog_file, file_type, data_file_type; type vendor_slog_file, file_type, data_file_type;

View file

@ -192,6 +192,7 @@
/data/vendor/radio(/.*)? u:object_r:radio_vendor_data_file:s0 /data/vendor/radio(/.*)? u:object_r:radio_vendor_data_file:s0
/data/vendor/modem_stat(/.*)? u:object_r:modem_stat_data_file:s0 /data/vendor/modem_stat(/.*)? u:object_r:modem_stat_data_file:s0
/data/vendor/log(/.*)? u:object_r:vendor_log_file:s0 /data/vendor/log(/.*)? u:object_r:vendor_log_file:s0
/data/vendor/log/hwc(/.*)? u:object_r:vendor_hwc_log_file:s0
/data/vendor/log/rfsd(/.*)? u:object_r:vendor_rfsd_log_file:s0 /data/vendor/log/rfsd(/.*)? u:object_r:vendor_rfsd_log_file:s0
/data/vendor/rild(/.*)? u:object_r:rild_vendor_data_file:s0 /data/vendor/rild(/.*)? u:object_r:rild_vendor_data_file:s0
/data/vendor/ss(/.*)? u:object_r:tee_data_file:s0 /data/vendor/ss(/.*)? u:object_r:tee_data_file:s0

View file

@ -6,6 +6,9 @@ allow hal_dumpstate_default sysfs_cpu:file r_file_perms;
allow hal_dumpstate_default vendor_usf_reg_edit:file execute_no_trans; allow hal_dumpstate_default vendor_usf_reg_edit:file execute_no_trans;
allow hal_dumpstate_default vendor_usf_stats:file execute_no_trans; allow hal_dumpstate_default vendor_usf_stats:file execute_no_trans;
allow hal_dumpstate_default vendor_hwc_log_file:dir r_dir_perms;
allow hal_dumpstate_default vendor_hwc_log_file:file r_file_perms;
allow hal_dumpstate_default vendor_rfsd_log_file:dir r_dir_perms; allow hal_dumpstate_default vendor_rfsd_log_file:dir r_dir_perms;
allow hal_dumpstate_default vendor_rfsd_log_file:file r_file_perms; allow hal_dumpstate_default vendor_rfsd_log_file:file r_file_perms;

View file

@ -52,3 +52,7 @@ vndbinder_use(hal_graphics_composer_default)
# allow HWC to get device_config_surface_flinger_native_boot_prop for adpf flags # allow HWC to get device_config_surface_flinger_native_boot_prop for adpf flags
get_prop(hal_graphics_composer_default, device_config_surface_flinger_native_boot_prop) get_prop(hal_graphics_composer_default, device_config_surface_flinger_native_boot_prop)
# allow HWC to write log file
allow hal_graphics_composer_default vendor_hwc_log_file:dir rw_dir_perms;
allow hal_graphics_composer_default vendor_hwc_log_file:file create_file_perms;