Add se-policies for google_camera_app from pro
- Found selinux violations on google_camera_app for these services which are fixed after these changes are included. Bug: 264490031 Change-Id: Ib6f4a8a548425b0b98ed9b69edff6c973b9cbe3e Signed-off-by: Dinesh Yadav <dkyadav@google.com>
This commit is contained in:
parent
9ea22dde19
commit
b8b2445251
1 changed files with 8 additions and 0 deletions
8
vendor/google_camera_app.te
vendored
8
vendor/google_camera_app.te
vendored
|
@ -9,7 +9,15 @@ hal_client_domain(google_camera_app, hal_power)
|
|||
|
||||
# Allow camera app to access the a subset of app services.
|
||||
allow google_camera_app app_api_service:service_manager find;
|
||||
allow google_camera_app audioserver_service:service_manager find;
|
||||
allow google_camera_app cameraserver_service:service_manager find;
|
||||
allow google_camera_app mediaextractor_service:service_manager find;
|
||||
allow google_camera_app mediametrics_service:service_manager find;
|
||||
allow google_camera_app mediaserver_service:service_manager find;
|
||||
|
||||
# Allows GCA to access the EdgeTPU device.
|
||||
allow google_camera_app edgetpu_app_service:service_manager find;
|
||||
allow google_camera_app edgetpu_device:chr_file { getattr read write ioctl map };
|
||||
|
||||
# Library code may try to access vendor properties, but should be denied
|
||||
dontaudit google_camera_app vendor_default_prop:file { getattr map open };
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue