From 998fa7f5c8856b224335f68f6f830352de801c8c Mon Sep 17 00:00:00 2001 From: Max Bires Date: Wed, 15 Feb 2017 18:14:27 -0800 Subject: [PATCH] Adding allows for audioserver.te Address following denials: denied { read } for pid=746 comm="audioserver" name="hw_platform" dev="sysfs" ino=50308 scontext=u:r:audioserver:s0 tcontext=u:object_r:sysfs_soc:s0 tclass=file denied { search } for pid=757 comm="audioserver" name="soc0" dev="sysfs" ino=50280 scontext=u:r:audioserver:s0 tcontext=u:object_r:sysfs_soc:s0 tclass=dir Bug: 34784662 Test: The above denials are no longer present during boot Change-Id: I8448bdb5fdf692fda342c11500c0bc45419ae6e9 --- sepolicy/audioserver.te | 3 +++ 1 file changed, 3 insertions(+) diff --git a/sepolicy/audioserver.te b/sepolicy/audioserver.te index 978b36e..02c801c 100644 --- a/sepolicy/audioserver.te +++ b/sepolicy/audioserver.te @@ -1,3 +1,6 @@ binder_call(audioserver, bootanim) allow audioserver perfd_socket:sock_file write; + +allow audioserver sysfs_soc:file r_file_perms; +allow audioserver sysfs_soc:dir search;