Remove unnecessary permissions.

Remove sysfs file permissions and use the generic type for
directories.

Bug:74213358
Test: Flash OTA.
Change-Id: I27a27972f01a273b4eb65d72dd8f2827c1a374af
This commit is contained in:
Joel Galenson
2018-03-06 13:32:07 -08:00
parent 5fa2e560d5
commit 278cab5f37

View File

@@ -22,13 +22,10 @@ allow hal_bootctl tmpfs:lnk_file r_file_perms;
# Read the sysfs to lookup what /dev/sgN device
# corresponds to the XBL partitions.
allow hal_bootctl sysfs:dir r_dir_perms;
allow hal_bootctl sysfs_type:dir r_dir_perms;
# Write to the XBL devices.
allow hal_bootctl xbl_block_device:blk_file rw_file_perms;
# Expose a socket for brokered boot message access for hal_oemlock.
allow hal_bootctl hal_bootctl_socket:sock_file create_file_perms;
allow hal_bootctl sysfs_scsi_devices_other:dir r_dir_perms;
allow hal_bootctl sysfs_scsi_devices_other:file r_file_perms;