Files
device_google_wahoo/sepolicy/hal_graphics_composer_default.te
Max Bires 6a6d8a7e80 Removing allow rule.
Allow rule was triggering a neverallow, missed due to a bug.
Test: The device builds

Change-Id: Ie79d15c294d798a0ed65ef4705636dc63576a76d
2017-03-28 16:00:38 -07:00

21 lines
975 B
Plaintext

# Binder access (for display.qservice)
# TODO(35706331): Remove once Graphics Composer HAL stops using Binder
typeattribute hal_graphics_composer_default binder_in_vendor_violators;
binder_service(hal_graphics_composer_default)
binder_use(hal_graphics_composer_default)
allow hal_graphics_composer_default surfaceflinger_service:service_manager { add find };
allow hal_graphics_composer_default sysfs_camera:dir search;
allow hal_graphics_composer_default sysfs_camera:file r_file_perms;
allow hal_graphics_composer_default sysfs_msm_subsys:dir search;
allow hal_graphics_composer_default sysfs_msm_subsys:file r_file_perms;
allow hal_graphics_composer_default sysfs_mdss_mdp_caps:file r_file_perms;
r_dir_file(hal_graphics_composer_default, sysfs_leds)
# HWC_UeventThread
allow hal_graphics_composer_default self:netlink_kobject_uevent_socket create_socket_perms_no_ioctl;
# Access /sys/devices/virtual/graphics/fb0
r_dir_file(hal_graphics_composer_default, sysfs_type)