From 94878fa0bbcf4f7cf677899d48a8d097a9d8343e Mon Sep 17 00:00:00 2001 From: Kyle Harrison Date: Thu, 12 Nov 2020 19:00:18 +0000 Subject: [PATCH] msm8974-common: sepolicy: Fix exported_camera_prop denials Change-Id: Ib3abf88a4c71fcd1510a9b1a3cd496b85379c8b2 --- sepolicy/common/app.te | 1 + sepolicy/common/system_server.te | 1 + sepolicy/common/zygote.te | 2 ++ 3 files changed, 4 insertions(+) create mode 100644 sepolicy/common/app.te diff --git a/sepolicy/common/app.te b/sepolicy/common/app.te new file mode 100644 index 0000000..f2f2bef --- /dev/null +++ b/sepolicy/common/app.te @@ -0,0 +1 @@ +get_prop(appdomain, exported_camera_prop); diff --git a/sepolicy/common/system_server.te b/sepolicy/common/system_server.te index 2c66830..8479534 100644 --- a/sepolicy/common/system_server.te +++ b/sepolicy/common/system_server.te @@ -10,5 +10,6 @@ allow system_server { allow system_server proc_last_kmsg:file r_file_perms; +get_prop(system_server, exported_camera_prop); get_prop(system_server, userspace_reboot_config_prop); get_prop(system_server, userspace_reboot_exported_prop); diff --git a/sepolicy/common/zygote.te b/sepolicy/common/zygote.te index a6e244a..a88579f 100644 --- a/sepolicy/common/zygote.te +++ b/sepolicy/common/zygote.te @@ -1 +1,3 @@ +get_prop(zygote, exported_camera_prop); + dontaudit zygote proc_cmdline:file r_file_perms;