Merge "sepolicy: Correct sepolicy for secure camera service"
This commit is contained in:
		
				
					committed by
					
						
						Gerrit - the friendly Code Review server
					
				
			
			
				
	
			
			
			
					commit
					c0ffc3fbb0
				
			
							
								
								
									
										2
									
								
								qva/vendor/common/seapp_contexts
									
									
									
									
										vendored
									
									
								
							
							
						
						
									
										2
									
								
								qva/vendor/common/seapp_contexts
									
									
									
									
										vendored
									
									
								
							@@ -28,3 +28,5 @@
 | 
			
		||||
#Add new domain for perfdump app
 | 
			
		||||
user=system seinfo=platform name=com.qualcomm.qti.perfdump domain=vendor_perfdump_app type=system_app_data_file
 | 
			
		||||
 | 
			
		||||
#Add new domain for secure camera service app
 | 
			
		||||
user=_app seinfo=platform name=com.qualcomm.qti.seccamservice:remote domain=vendor_seccam_app type=app_data_file levelfrom=all
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										4
									
								
								qva/vendor/common/seccam_app.te
									
									
									
									
										vendored
									
									
								
							
							
						
						
									
										4
									
								
								qva/vendor/common/seccam_app.te
									
									
									
									
										vendored
									
									
								
							@@ -32,8 +32,8 @@ net_domain(vendor_seccam_app)
 | 
			
		||||
hal_client_domain(vendor_seccam_app, vendor_hal_seccam);
 | 
			
		||||
hal_client_domain(vendor_seccam_app, vendor_hal_qteeconnector);
 | 
			
		||||
 | 
			
		||||
allow vendor_seccam_app system_app_data_file:dir create_dir_perms;
 | 
			
		||||
allow vendor_seccam_app system_app_data_file:file create_file_perms;
 | 
			
		||||
allow vendor_seccam_app app_data_file:dir create_dir_perms;
 | 
			
		||||
allow vendor_seccam_app app_data_file:file create_file_perms;
 | 
			
		||||
allow vendor_seccam_app { activity_service app_api_service } :service_manager find;
 | 
			
		||||
allow vendor_seccam_app self:qipcrtr_socket create_socket_perms_no_ioctl;
 | 
			
		||||
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										3
									
								
								qva/vendor/common/sysmonapp/seapp_contexts
									
									
									
									
										vendored
									
									
								
							
							
						
						
									
										3
									
								
								qva/vendor/common/sysmonapp/seapp_contexts
									
									
									
									
										vendored
									
									
								
							@@ -28,6 +28,3 @@
 | 
			
		||||
# sysmonapp applications
 | 
			
		||||
user=_app seinfo=sysmonapp domain=vendor_sysmonapp_app name=com.qualcomm.sysmonappInternal type=app_data_file levelFrom=all
 | 
			
		||||
user=_app seinfo=sysmonapp domain=vendor_sysmonapp_app name=com.qualcomm.qti.sysmonappExternal type=app_data_file levelFrom=all
 | 
			
		||||
 | 
			
		||||
#Add new domain for secure camera service app
 | 
			
		||||
user=system seinfo=platform name=com.qualcomm.qti.seccamservice:remote domain=vendor_seccam_app type=system_app_data_file
 | 
			
		||||
 
 | 
			
		||||
		Reference in New Issue
	
	Block a user