universal7580: sepolicy: allow rild ioctls on /efs/nv_data.bin* files
authorDanny Wood <danwood76@gmail.com>
Tue, 3 Dec 2019 12:43:54 +0000 (12:43 +0000)
committerDanny Wood <danwood76@gmail.com>
Tue, 10 Mar 2020 15:25:58 +0000 (15:25 +0000)
Change-Id: I3e4f35df51dd2bbe465035750a52c834d5d15f65

sepolicy/rild.te

index 1299f837ab5ecfcca7db669add0e73fb1bf1d350..d743cacbd72fc501bcc466f9305d6dbcb2e853a8 100644 (file)
@@ -2,10 +2,13 @@
 allow rild self:capability chown;
 
 # Allow additiional efs access
-allow rild bin_nv_data_efs_file:file create_file_perms;
 r_dir_file(rild, imei_efs_file);
 r_dir_file(rild, app_efs_file);
 
+# /efs/nv_data.bin
+allow rild bin_nv_data_efs_file:file create_file_perms;
+allowxperm rild bin_nv_data_efs_file:file ioctl { 0x6601 0x6602 };
+
 # audioserver
 r_dir_file(rild, audioserver);