device_google_zuma/vendor/vendor_init.te
Dinesh Yadav 100dd2387d Add sepolicy for gxp_logging service to report metrics [RESTRICT AUTOMERGE]
gxp_logging service will periodically check the sysfs files exposed by
the gxp kernel driver and report stats to Suez framework.
These policies are needed to report the metrics.

Tested:
Found no violation with these policies on a P23 device

Bug: 278514198
Change-Id: I8c3e57dfe4e9a6caab425f2424d07e83f5e7b9c6
Signed-off-by: Dinesh Yadav <dkyadav@google.com>
2023-06-13 03:37:56 +00:00

44 lines
1.2 KiB
Text

# Fingerprint property
set_prop(vendor_init, vendor_fingerprint_prop)
# Battery harness mode property
set_prop(vendor_init, vendor_battery_defender_prop)
set_prop(vendor_init, logpersistd_logging_prop)
allow vendor_init proc_dirty:file w_file_perms;
allow vendor_init proc_sched:file w_file_perms;
allow vendor_init sg_device:chr_file r_file_perms;
allow vendor_init bootdevice_sysdev:file create_file_perms;
allow vendor_init modem_img_file:filesystem { getattr };
# Allow for checking NSP permissions
allow vendor_init tee_data_file:lnk_file read;
userdebug_or_eng(`
allow vendor_init vendor_init:lockdown { integrity };
')
# Camera vendor property
set_prop(vendor_init, vendor_camera_prop)
# NFC vendor property
set_prop(vendor_init, vendor_nfc_prop)
# SecureElement vendor property
set_prop(vendor_init, vendor_secure_element_prop)
# USB property
set_prop(vendor_init, vendor_usb_config_prop)
set_prop(vendor_init, vendor_ssrdump_prop)
# Mali
set_prop(vendor_init, vendor_arm_runtime_option_prop)
# ArmNN
set_prop(vendor_init, vendor_armnn_config_prop)
# MM
allow vendor_init proc_watermark_scale_factor:file w_file_perms;
# Gxp
set_prop(vendor_init, vendor_gxp_prop)