sdm845-common: sepolicy: Copy over public_vendor_default_prop rules from qcom sepolicy
* This addresses many denials introduced by enabling vendor and system property isolation. Change-Id: I24e04fc24be32698c7fdae4b28e90e9c20161a77
This commit is contained in:
parent
26cf3e0528
commit
8936a7fda0
4 changed files with 13 additions and 0 deletions
2
sepolicy/private/domain.te
Normal file
2
sepolicy/private/domain.te
Normal file
|
@ -0,0 +1,2 @@
|
||||||
|
# Allow domain to get public_vendor_default_prop
|
||||||
|
get_prop(domain, public_vendor_default_prop)
|
|
@ -1 +1,2 @@
|
||||||
|
type public_vendor_default_prop, property_type;
|
||||||
type vendor_camera_prop, property_type;
|
type vendor_camera_prop, property_type;
|
||||||
|
|
7
sepolicy/private/property_contexts
Normal file
7
sepolicy/private/property_contexts
Normal file
|
@ -0,0 +1,7 @@
|
||||||
|
ro.vendor.graphics.memory u:object_r:public_vendor_default_prop:s0
|
||||||
|
vendor.debug.egl.changepixelformat u:object_r:public_vendor_default_prop:s0
|
||||||
|
vendor.debug.egl.profiler u:object_r:public_vendor_default_prop:s0
|
||||||
|
vendor.debug.egl.swapinterval u:object_r:public_vendor_default_prop:s0
|
||||||
|
vendor.debug.prerotation.disable u:object_r:public_vendor_default_prop:s0
|
||||||
|
vendor.debug.rs. u:object_r:public_vendor_default_prop:s0
|
||||||
|
vendor.dump.gpu.output u:object_r:public_vendor_default_prop:s0
|
|
@ -1,2 +1,5 @@
|
||||||
|
# Allow vendor_init to set public_vendor_default_prop
|
||||||
|
set_prop(vendor_init, public_vendor_default_prop)
|
||||||
|
|
||||||
# Allow vendor_init to set vendor_camera_prop
|
# Allow vendor_init to set vendor_camera_prop
|
||||||
set_prop(vendor_init, vendor_camera_prop)
|
set_prop(vendor_init, vendor_camera_prop)
|
||||||
|
|
Loading…
Reference in a new issue