msm8974-common: sepolicy: Label sysfs_leds, resolve denials

* avc: denied { search } for name="leds" dev="sysfs" ino=7437
  scontext=u:r:hal_sensors_default:s0
  tcontext=u:object_r:sysfs_leds:s0 tclass=dir permissive=1
* avc: denied { setattr } for name="led_r" dev="sysfs" ino=25718
  scontext=u:r:init:s0 tcontext=u:object_r:sysfs:s0 tclass=file
  permissive=1

Change-Id: I8840e28b3aa72e60d5c15cad66f043a36a15c771
This commit is contained in:
Kevin F. Haggerty 2018-11-14 07:21:38 -07:00
parent 0e66ee2593
commit bb196ad94b
No known key found for this signature in database
GPG Key ID: 6D95512933112729
3 changed files with 7 additions and 0 deletions

View File

@ -53,5 +53,10 @@
/sys/bus/iio/devices(/.*)? u:object_r:sysfs_iio:s0
/sys/devices/[a-f0-9]+\.spi/spi_master/spi[0-9]+/spi[0-9]+\.0/iio:device[0-9](/.*)? u:object_r:sysfs_iio:s0
# sysfs - leds
/sys/devices/i2c\.[0-9]+/i2c-[0-9]+/[0-9]+-[a-z0-9]+/leds(/.*)? u:object_r:sysfs_leds:s0
/sys/devices/i2c\.[0-9]+/i2c-[0-9]+/[0-9]+-[a-z0-9]+/max[a-z0-9]+-led/leds(/.*)? u:object_r:sysfs_leds:s0
/sys/devices/leds-qpnp-[0-9]+/leds(/.*)? u:object_r:sysfs_leds:s0
# sysfs - mdnie
/sys/devices/virtual/mdnie/mdnie(/.*)? u:object_r:sysfs_mdnie:s0

View File

@ -1,6 +1,7 @@
allow hal_sensors_default {
sysfs_batteryinfo
sysfs_graphics
sysfs_leds
}:dir search;
allow hal_sensors_default {

View File

@ -9,5 +9,6 @@ allow init {
sysfs_graphics
sysfs_iio
sysfs_input
sysfs_leds
sysfs_mdnie
}:file setattr;