device_google_zumapro/legacy/zuma/vendor/tee.te
Donnie Pollitz 662dc87e32 trusty: Fix selinux denials for block devices
Bug: 312894027
Test: Confirmed avc denial is gone on boot
Change-Id: Iaa87cdef24214a2b6f6eba2af917c03bbbb4bfb5
Signed-off-by: Donnie Pollitz <donpollitz@google.com>
2023-11-28 09:20:41 +01:00

15 lines
461 B
Text

# Handle wake locks
wakelock_use(tee)
allow tee persist_ss_file:file create_file_perms;
allow tee persist_ss_file:dir create_dir_perms;
allow tee persist_file:dir r_dir_perms;
allow tee mnt_vendor_file:dir r_dir_perms;
allow tee tee_data_file:dir rw_dir_perms;
allow tee tee_data_file:lnk_file r_file_perms;
allow tee block_device:dir search;
# Allow storageproxyd access to gsi_public_metadata_file
read_fstab(tee)
set_prop(tee, vendor_trusty_storage_prop)