diff --git a/sepolicy/vendor/kernel.te b/sepolicy/vendor/kernel.te index c5cbb8b3..23686463 100644 --- a/sepolicy/vendor/kernel.te +++ b/sepolicy/vendor/kernel.te @@ -9,3 +9,6 @@ allow kernel vendor_firmware_file:file r_file_perms; allow kernel vendor_firmware_file:lnk_file read; dontaudit kernel kernel:system module_request; + +allow kernel debugfs_ipc:dir search; +allow kernel persist_file:dir search; diff --git a/sepolicy/vendor/netd.te b/sepolicy/vendor/netd.te index cc679185..b26f9751 100644 --- a/sepolicy/vendor/netd.te +++ b/sepolicy/vendor/netd.te @@ -1,4 +1,4 @@ allow netd sysfs_net:file w_file_perms; dontaudit netd kernel:system module_request; -dontaudit netd self:system module_request; +dontaudit netd self:capability sys_module;