sepolicy: Give read/write permission to vender_gles_data_file
These rules are missed while porting the policies from Android P
to Android Q.
Adressing the following denial:
type=1400 audit(14866.629:43): avc: denied { search } for comm="HwBinder:753_1"
name="gpu" dev="sda9" ino=376 scontext=u:r:hal_graphics_allocator_default:s0
tcontext=u:object_r:vendor_gles_data_file:s0 tclass=dir permissive=0
Change-Id: I24434be8d895d5dab8e5c24643c8be48f20d8673
			
			
This commit is contained in:
		
							
								
								
									
										3
									
								
								generic/vendor/test/domain.te
									
									
									
									
										vendored
									
									
								
							
							
						
						
									
										3
									
								
								generic/vendor/test/domain.te
									
									
									
									
										vendored
									
									
								
							@@ -42,4 +42,7 @@ r_dir_file({domain - isolated_app}, sysfs_kgsl_snapshot);
 | 
			
		||||
allow domain coredump_file:dir create_dir_perms;
 | 
			
		||||
allow domain coredump_file:file create_file_perms;
 | 
			
		||||
allow domain coredump_file:dir rw_dir_perms;
 | 
			
		||||
r_dir_file({domain - coredomain - hal_configstore_default}, vendor_gles_data_file);
 | 
			
		||||
allow {domain - coredomain - hal_configstore_default} vendor_gles_data_file:dir create_dir_perms;
 | 
			
		||||
allow {domain - coredomain - hal_configstore_default} vendor_gles_data_file:file create_file_perms;
 | 
			
		||||
')
 | 
			
		||||
 
 | 
			
		||||
		Reference in New Issue
	
	Block a user