From 6b3890ee091e667a3c07b98619f3b6352970f64f Mon Sep 17 00:00:00 2001 From: Kyle Harrison Date: Thu, 12 Nov 2020 19:00:18 +0000 Subject: [PATCH] universal7580: sepolicy: Fix exported_camera_prop denials Change-Id: Ib3abf88a4c71fcd1510a9b1a3cd496b85379c8b2 --- sepolicy/app.te | 1 + sepolicy/system_server.te | 1 + sepolicy/zygote.te | 2 ++ 3 files changed, 4 insertions(+) create mode 100644 sepolicy/app.te diff --git a/sepolicy/app.te b/sepolicy/app.te new file mode 100644 index 0000000..f2f2bef --- /dev/null +++ b/sepolicy/app.te @@ -0,0 +1 @@ +get_prop(appdomain, exported_camera_prop); diff --git a/sepolicy/system_server.te b/sepolicy/system_server.te index f91df76..cdb2a86 100644 --- a/sepolicy/system_server.te +++ b/sepolicy/system_server.te @@ -56,5 +56,6 @@ allow system_server proc_input_devices:file r_file_perms; unix_socket_connect(system_server, property, gpsd) +get_prop(system_server, exported_camera_prop); get_prop(system_server, userspace_reboot_exported_prop); get_prop(system_server, userspace_reboot_config_prop); diff --git a/sepolicy/zygote.te b/sepolicy/zygote.te index a6e244a..40dd7d6 100644 --- a/sepolicy/zygote.te +++ b/sepolicy/zygote.te @@ -1 +1,3 @@ dontaudit zygote proc_cmdline:file r_file_perms; + +get_prop(zygote, exported_camera_prop); -- 2.20.1