summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorMarco Nelissen <marcone@google.com>2022-02-03 19:26:13 +0000
committerAutomerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>2022-02-03 19:26:13 +0000
commita958f9524fe59560ef50ff709f8d14117903d703 (patch)
tree3432c23bc12a8562935ba4569b5edfad136f29e9
parent9a60373b2a3ace767aadf380ca2f5229f226b353 (diff)
parent8e57b17184b998896351fcd47a74f9daa95269dd (diff)
downloadtrusty-a958f9524fe59560ef50ff709f8d14117903d703.tar.gz
Fix Trusty log file permissions and ownership am: 842a0481a5 am: bcda646ab5 am: 8e57b17184
Original change: https://android-review.googlesource.com/c/device/generic/trusty/+/1969940 Change-Id: I51510d20930312159516ea131a27912f116b9d71
-rw-r--r--sepolicy/device.te1
-rw-r--r--sepolicy/file_contexts1
-rw-r--r--sepolicy/logd.te2
-rw-r--r--ueventd.qemu_trusty.rc1
4 files changed, 5 insertions, 0 deletions
diff --git a/sepolicy/device.te b/sepolicy/device.te
new file mode 100644
index 0000000..92eda83
--- /dev/null
+++ b/sepolicy/device.te
@@ -0,0 +1 @@
+type logbuffer_device, dev_type;
diff --git a/sepolicy/file_contexts b/sepolicy/file_contexts
index 9e27b2e..ccfee13 100644
--- a/sepolicy/file_contexts
+++ b/sepolicy/file_contexts
@@ -1,4 +1,5 @@
/dev/trusty-ipc-dev0 u:object_r:tee_device:s0
+/dev/trusty-log0 u:object_r:logbuffer_device:s0
/dev/vport3p1 u:object_r:rpmb_virt_device:s0
/dev/vport3p2 u:object_r:spi_virt_device:s0
/vendor/bin/dhcpclient u:object_r:dhcpclient_exec:s0
diff --git a/sepolicy/logd.te b/sepolicy/logd.te
new file mode 100644
index 0000000..cc55e20
--- /dev/null
+++ b/sepolicy/logd.te
@@ -0,0 +1,2 @@
+r_dir_file(logd, logbuffer_device)
+allow logd logbuffer_device:chr_file r_file_perms;
diff --git a/ueventd.qemu_trusty.rc b/ueventd.qemu_trusty.rc
index b24d068..7e46bba 100644
--- a/ueventd.qemu_trusty.rc
+++ b/ueventd.qemu_trusty.rc
@@ -2,3 +2,4 @@
/dev/vport3p1 0660 system system
/dev/vport3p2 0660 system system
/dev/trusty-ipc-dev0 0660 system drmrpc
+/dev/trusty-log0 0660 system system