sepolicy: Assign sysfs nodes to sensors label

Assign sysfs nodes to sensors label to avoid avc denials
in enforcing mode.

Change-Id: I5377d47b87a1abb1bc92a359de573358a0426678
This commit is contained in:
Shaikh Shadul
2017-10-05 17:41:04 +05:30
committed by Gerrit - the friendly Code Review server
parent c8ebdec9c9
commit 47ac73576d

View File

@@ -64,3 +64,18 @@
# System files
/(vendor|system/vendor)/bin/hw/vendor\.google_clockwork\.sidekickgraphics@1\.0-service u:object_r:hal_sidekickgraphics_default_exec:s0
###################################
# sysfs files
#
/sys/devices/soc/[a-z0-9]+.i2c/i2c-[0-9]/[0-9]-[a-z0-9]+/input/input[0-9]/MPU6050-accel(/.*)? u:object_r:sysfs_sensors:s0
/sys/devices/soc/[a-z0-9]+.i2c/i2c-[0-9]/[0-9]-[a-z0-9]+/input/input[0-9]/MPU6050-gyro(/.*)? u:object_r:sysfs_sensors:s0
/sys/devices/soc/[a-z0-9]+.i2c/i2c-[0-9]/[0-9]-[a-z0-9]+/input/input[0-9]/apds9930-light(/.*)? u:object_r:sysfs_sensors:s0
/sys/devices/soc/[a-z0-9]+.i2c/i2c-[0-9]/[0-9]-[a-z0-9]+/input/input[0-9]/apds9930-proximity(/.*)? u:object_r:sysfs_sensors:s0
/sys/devices/soc/[a-z0-9]+.i2c/i2c-[0-9]/[0-9]-[a-z0-9]+/input/input[0-9]/compass(/.*)? u:object_r:sysfs_sensors:s0
/sys/devices/soc/[a-z0-9]+.i2c/i2c-[0-9]/[0-9]-[a-z0-9]+/input/input[0-9]/bma2x2-accel(/.*)? u:object_r:sysfs_sensors:s0
/sys/devices/soc/[a-z0-9]+.i2c/i2c-[0-9]/[0-9]-[a-z0-9]+/input/input[0-9]/ltr553-light(/.*)? u:object_r:sysfs_sensors:s0
/sys/devices/soc/[a-z0-9]+.i2c/i2c-[0-9]/[0-9]-[a-z0-9]+/input/input[0-9]/ltr553-proximity(/.*)? u:object_r:sysfs_sensors:s0
/sys/devices/soc/[a-z0-9]+.i2c/i2c-[0-9]/[0-9]-[a-z0-9]+/input/input[0-9]/ap3426-light(/.*)? u:object_r:sysfs_sensors:s0
/sys/devices/soc/[a-z0-9]+.i2c/i2c-[0-9]/[0-9]-[a-z0-9]+/input/input[0-9]/ap3426-proximity(/.*)? u:object_r:sysfs_sensors:s0
/sys/devices/virtual/input/input[0-9]/akm8963-mag(/.*)? u:object_r:sysfs_sensors:s0