diff --git a/sepolicy/vendor/dontaudit.te b/sepolicy/vendor/dontaudit.te index 84547c0..7e55ad9 100644 --- a/sepolicy/vendor/dontaudit.te +++ b/sepolicy/vendor/dontaudit.te @@ -2,3 +2,7 @@ dontaudit { hal_camera_default rild } default_prop:file r_file_perms; + +# Apps are no longer allowed open access to /dev/ashmem, unless they +# target API level < Q. +dontaudit untrusted_app ashmem_device:chr_file open;