From 895c0fb6fbfef5d648ca5749ed594369a1e6b1cd Mon Sep 17 00:00:00 2001 From: Alexander Diewald Date: Thu, 9 Nov 2017 14:42:36 +0100 Subject: shinano: Resolve mlog_qmi related denials. * Create socket perms for the own socket. * Allow access to qseecom. Change-Id: Ifbd5f08f1d9bbbadc3ba94ad79d1e8f7f5286635 Signed-off-by: Alexander Diewald --- sepolicy/mlog_qmi.te | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) (limited to 'sepolicy') diff --git a/sepolicy/mlog_qmi.te b/sepolicy/mlog_qmi.te index d0332e3..d41a788 100644 --- a/sepolicy/mlog_qmi.te +++ b/sepolicy/mlog_qmi.te @@ -5,7 +5,11 @@ type mlog_qmi_exec, exec_type, file_type; init_daemon_domain(mlog_qmi) allow mlog_qmi self:capability { net_raw net_bind_service }; -allow mlog_qmi self:socket read; +allow mlog_qmi self:socket create_socket_perms_no_ioctl; # Access to /dev/smem_log allow mlog_qmi smem_log_device:chr_file rw_file_perms; + +# qseecom +allow mlog_qmi tee_device:chr_file rw_file_perms; +allowxperm mlog_qmi tee_device:chr_file ioctl qseecom_sock_ipc_ioctls; -- cgit v1.2.3