sm6375-common: sepolicy: Allow fp hal to access graphics device

* I HwBinder:1502_1: type=1400 audit(0.0:862): avc:  denied  { read write } for  name="card0" dev="tmpfs" ino=26702 scontext=u:r:hal_fingerprint_default:s0 tcontext=u:object_r:graphics_device:s0 tclass=chr_file permissive=1
* I HwBinder:1502_1: type=1400 audit(0.0:863): avc:  denied  { open } for  path="/dev/dri/card0" dev="tmpfs" ino=26702 scontext=u:r:hal_fingerprint_default:s0 tcontext=u:object_r:graphics_device:s0 tclass=chr_file permissive=1
* I HwBinder:1502_1: type=1400 audit(0.0:864): avc:  denied  { ioctl } for  path="/dev/dri/card0" dev="tmpfs" ino=26702 ioctlcmd=0x649f scontext=u:r:hal_fingerprint_default:s0 tcontext=u:object_r:graphics_device:s0 tclass=chr_file permissive=1

Change-Id: Iccfda81d6ab92f43c988ab2ff85577dffbcd5699
This commit is contained in:
Anand S 2024-08-10 20:16:00 +05:30
parent a7f57c0aa4
commit 5797d151b5
No known key found for this signature in database
GPG key ID: 3B2983FA448B3D61
2 changed files with 4 additions and 0 deletions

View file

@ -43,6 +43,9 @@
/(mnt/vendor/persist|persist)/chargeonly(/.*)? u:object_r:persist_chargeonly_file:s0
/(vendor|system/vendor)/bin/charge_only_mode u:object_r:charge_only_exec:s0
# DRI
/dev/dri/card[0-4] u:object_r:graphics_device:s0
# Fingerprint
/(mnt/vendor/persist|persist)/egis(/.*)? u:object_r:vendor_persist_egis_file:s0
/(mnt/vendor/persist|persist)/fps(/.*)? u:object_r:vendor_persist_fps_file:s0

View file

@ -3,6 +3,7 @@ allow hal_fingerprint_default {
egis_device
goodix_device
tee_device
graphics_device
}: chr_file rw_file_perms;
allow hal_fingerprint_default self:binder { call transfer };