diff --git a/sepolicy/common/app.te b/sepolicy/common/app.te new file mode 100644 index 0000000..f2f2bef --- /dev/null +++ b/sepolicy/common/app.te @@ -0,0 +1 @@ +get_prop(appdomain, exported_camera_prop); diff --git a/sepolicy/common/system_server.te b/sepolicy/common/system_server.te index 2c66830..8479534 100644 --- a/sepolicy/common/system_server.te +++ b/sepolicy/common/system_server.te @@ -10,5 +10,6 @@ allow system_server { allow system_server proc_last_kmsg:file r_file_perms; +get_prop(system_server, exported_camera_prop); get_prop(system_server, userspace_reboot_config_prop); get_prop(system_server, userspace_reboot_exported_prop); diff --git a/sepolicy/common/zygote.te b/sepolicy/common/zygote.te index a6e244a..a88579f 100644 --- a/sepolicy/common/zygote.te +++ b/sepolicy/common/zygote.te @@ -1 +1,3 @@ +get_prop(zygote, exported_camera_prop); + dontaudit zygote proc_cmdline:file r_file_perms;