From 51b7479a3d86cb145ab13e09c7abb2e94671c62d Mon Sep 17 00:00:00 2001 From: Michael Bestas Date: Tue, 17 Dec 2019 19:14:21 +0200 Subject: [PATCH] davinci: sepolicy: Silence harmless QCOM denials Change-Id: Iad1e2c0e654a4a46da76a57ece63dc4f35761d50 --- sepolicy/vendor/hal_audio_default.te | 2 ++ sepolicy/vendor/init.te | 2 ++ sepolicy/vendor/priv_app.te | 3 +++ 3 files changed, 7 insertions(+) create mode 100644 sepolicy/vendor/init.te create mode 100644 sepolicy/vendor/priv_app.te diff --git a/sepolicy/vendor/hal_audio_default.te b/sepolicy/vendor/hal_audio_default.te index 412fbca..25a89c8 100644 --- a/sepolicy/vendor/hal_audio_default.te +++ b/sepolicy/vendor/hal_audio_default.te @@ -6,3 +6,5 @@ r_dir_file(hal_audio_default, persist_audio_file) set_prop(hal_audio_default, vendor_audio_prop) allow hal_audio_default audio_socket:sock_file rw_file_perms; + +dontaudit hal_audio_default sysfs:dir read; diff --git a/sepolicy/vendor/init.te b/sepolicy/vendor/init.te new file mode 100644 index 0000000..870c379 --- /dev/null +++ b/sepolicy/vendor/init.te @@ -0,0 +1,2 @@ +dontaudit init bt_firmware_file:filesystem getattr; +dontaudit init firmware_file:filesystem getattr; diff --git a/sepolicy/vendor/priv_app.te b/sepolicy/vendor/priv_app.te new file mode 100644 index 0000000..f90ff52 --- /dev/null +++ b/sepolicy/vendor/priv_app.te @@ -0,0 +1,3 @@ +dontaudit priv_app bt_firmware_file:filesystem getattr; +dontaudit priv_app firmware_file:filesystem getattr; +dontaudit priv_app mnt_vendor_file:dir search;