universal7580: sepolicy: address init denials
[GitHub/LineageOS/android_device_samsung_universal7580-common.git] / sepolicy / rild.te
CommitLineData
c1a50488 1# Allow rild to change perms
ee133eb7 2allow rild self:capability chown;
c1a50488
DW
3
4# Allow additiional efs access
ee133eb7
JA
5r_dir_file(rild, imei_efs_file);
6r_dir_file(rild, app_efs_file);
c1a50488 7
d92a2f87
DW
8# /efs/nv_data.bin
9allow rild bin_nv_data_efs_file:file create_file_perms;
10allowxperm rild bin_nv_data_efs_file:file ioctl { 0x6601 0x6602 };
11
ee133eb7
JA
12# audioserver
13r_dir_file(rild, audioserver);
c1a50488
DW
14
15# /dev/mbin0
16allow rild block_device:dir r_dir_perms;
17allow rild emmcblk_device:blk_file r_file_perms;
18
19# /dev/umts_boot0, /dev/umts_ipc0
20allow rild mif_device:chr_file rw_file_perms;
21
22# /sys/devices/virtual/misc/multipdp/waketime
c63278d0 23allow rild sysfs_multipdp:file rw_file_perms;
c1a50488 24
23070e73
JL
25allow rild sysfs_input:file rw_file_perms;
26
c1a50488
DW
27# /proc/sys/net/ipv6/conf/*/accept_ra_defrtr
28allow rild proc_net:file rw_file_perms;
29
ee133eb7 30r_dir_file(rild, gpsd);
c1a50488 31
c63278d0
DW
32allow rild proc_qtaguid_stat:file r_file_perms;
33
c1a50488 34# rild reads /proc/pid/cmdline of mediaserver
ee133eb7 35r_dir_file(rild, mediaserver);
c1a50488
DW
36
37# /data/misc/radio/*
38allow rild radio_data_file:dir rw_dir_perms;
39allow rild radio_data_file:file create_file_perms;
40# /data/data/com.android.providers.telephony/databases/telephony.db
41allow rild radio_data_file:lnk_file r_file_perms;
42
43# sdcard/SDET_PLMN/input/MNCMCC.txt
ee133eb7
JA
44allow rild storage_file:dir r_dir_perms;
45allow rild storage_file:lnk_file r_file_perms;
46allow rild mnt_user_file:dir r_dir_perms;
47allow rild mnt_user_file:lnk_file r_file_perms;
c1a50488
DW
48
49# Modem firmware download
50allow rild radio_block_device:blk_file r_file_perms;
51
52# persist.ril.modem.board
53set_prop(modemloader, radio_prop)
54
55# /dev/knox_kap
56allow rild knox_device:chr_file r_file_perms;
57
58# /data/media/0
ee133eb7 59allow rild media_rw_data_file:dir r_dir_perms;