sepolicy: Give read/write permission to vender_gles_data_file

These rules are missed while porting the policies from Android P
to Android Q.

Adressing the following denial:

type=1400 audit(14866.629:43): avc: denied { search } for comm="HwBinder:753_1"
name="gpu" dev="sda9" ino=376 scontext=u:r:hal_graphics_allocator_default:s0
tcontext=u:object_r:vendor_gles_data_file:s0 tclass=dir permissive=0

Change-Id: I24434be8d895d5dab8e5c24643c8be48f20d8673
This commit is contained in:
Rahul Janga
2019-06-13 18:02:53 +05:30
parent ed9d8b83c9
commit 872951efad

View File

@@ -42,4 +42,7 @@ r_dir_file({domain - isolated_app}, sysfs_kgsl_snapshot);
allow domain coredump_file:dir create_dir_perms;
allow domain coredump_file:file create_file_perms;
allow domain coredump_file:dir rw_dir_perms;
r_dir_file({domain - coredomain - hal_configstore_default}, vendor_gles_data_file);
allow {domain - coredomain - hal_configstore_default} vendor_gles_data_file:dir create_dir_perms;
allow {domain - coredomain - hal_configstore_default} vendor_gles_data_file:file create_file_perms;
')