diff --git a/sepolicy/vendor/netmgrd.te b/sepolicy/vendor/netmgrd.te index 5660ce31..ebe12bbc 100644 --- a/sepolicy/vendor/netmgrd.te +++ b/sepolicy/vendor/netmgrd.te @@ -27,11 +27,6 @@ allow netmgrd sysfs_soc:file r_file_perms; allow netmgrd sysfs_msm_subsys:dir r_dir_perms; allow netmgrd sysfs_msm_subsys:file r_file_perms; -allow netmgrd system_file:file lock; -# TODO(b/111243627): Expose required system components via separate types once -# we have enough information about what is needed by netmgrd. -auditallow netmgrd system_file:file lock; - r_dir_file(netmgrd, sysfs_msm_subsys) wakelock_use(netmgrd) @@ -54,10 +49,6 @@ dontaudit netmgrd kernel:system { module_request }; allow netmgrd proc_net:file rw_file_perms; allow netmgrd netmgr_data_file:dir rw_dir_perms; allow netmgrd netmgr_data_file:file create_file_perms; -allow netmgrd system_file:file execute_no_trans; -# TODO(b/117232795): Figure out what is executed by netmgrd in /system and route -# that dependency to netutils_wrapper. -auditallow netmgrd system_file:file execute_no_trans; allow netmgrd self:capability { net_admin net_raw setgid setpcap setuid };