Allow kernel to access firmware and zram

Bug: 260522245
Change-Id: I964ac1e30e0181f4d6edc71f2e066b7bd515186b
This commit is contained in:
Wilson Sung 2023-02-08 04:34:12 +08:00
parent 9cce214473
commit 856d2c480e
2 changed files with 6 additions and 5 deletions

View file

@ -1,10 +1,6 @@
# b/260522245 # b/260522245
dontaudit kernel per_boot_file:file { read };
dontaudit kernel same_process_hal_file:file { open }; dontaudit kernel same_process_hal_file:file { open };
dontaudit kernel same_process_hal_file:file { read }; dontaudit kernel same_process_hal_file:file { read };
dontaudit kernel vendor_fw_file:dir { search };
dontaudit kernel vendor_fw_file:file { open };
dontaudit kernel vendor_fw_file:file { read };
dontaudit kernel vendor_regmap_debugfs:dir { search }; dontaudit kernel vendor_regmap_debugfs:dir { search };
# b/261650972 # b/261650972
dontaudit kernel vendor_battery_debugfs:dir { search }; dontaudit kernel vendor_battery_debugfs:dir { search };
@ -23,4 +19,4 @@ dontaudit kernel kernel:capability { net_bind_service };
# b/264490052 # b/264490052
userdebug_or_eng(` userdebug_or_eng(`
permissive kernel; permissive kernel;
') ')

5
vendor/kernel.te vendored Normal file
View file

@ -0,0 +1,5 @@
allow kernel vendor_fw_file:dir search;
allow kernel vendor_fw_file:file r_file_perms;
# ZRam
allow kernel per_boot_file:file r_file_perms;