universal7580: sepolicy: address init denials
[GitHub/LineageOS/android_device_samsung_universal7580-common.git] / sepolicy / fingerprintd.te
1 # allow hal_fingerprint_default to communicate with various devices
2 binder_call(system_app, hal_fingerprint_default)
3
4 # kernel fp device
5 allow hal_fingerprint_default fingerprint_device:chr_file rw_file_perms;
6
7 # secure memory device
8 allow hal_fingerprint_default secmem_device:chr_file rw_file_perms;
9
10 # trust zone device
11 allow hal_fingerprint_default tee_device:chr_file rw_file_perms;
12 allow hal_fingerprint_default tee:unix_stream_socket connectto;
13
14 # /data/biometrics/*
15 allow hal_fingerprint_default fingerprintd_data_file:dir create_dir_perms;
16 allow hal_fingerprint_default fingerprintd_data_file:file create_file_perms;