summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorTreehugger Robot <android-test-infra-autosubmit@system.gserviceaccount.com>2023-12-11 07:31:03 +0000
committerAndroid (Google) Code Review <android-gerrit@google.com>2023-12-11 07:31:03 +0000
commit46cd7460120f36f6108f04ecaf1d0d17078ca3f9 (patch)
tree2a91bf02cc6dca92183efa568e0025101626891d
parentc42d6625f58837ee0a9cebbdf43f6d7174fe3a54 (diff)
parent548c2f184d9b8aeca9d75bf35319fef591d05a85 (diff)
downloadgs101-sepolicy-46cd7460120f36f6108f04ecaf1d0d17078ca3f9.tar.gz
Merge "Fix rlsservice sepolicy" into main
-rw-r--r--tracking_denials/bug_map1
-rw-r--r--whitechapel/vendor/google/dumpstate.te2
-rw-r--r--whitechapel/vendor/google/rlsservice.te4
3 files changed, 5 insertions, 2 deletions
diff --git a/tracking_denials/bug_map b/tracking_denials/bug_map
index 0e21112..5ec3d60 100644
--- a/tracking_denials/bug_map
+++ b/tracking_denials/bug_map
@@ -1,6 +1,5 @@
chre vendor_data_file dir b/301948771
dump_modem device chr_file b/305600375
-dumpstate rlsservice binder b/309379598
dumpstate virtual_camera binder b/312894628
dumpstate virtual_camera process b/312894628
hal_power_default hal_power_default capability b/240632824
diff --git a/whitechapel/vendor/google/dumpstate.te b/whitechapel/vendor/google/dumpstate.te
index e715ad9..f5be2a8 100644
--- a/whitechapel/vendor/google/dumpstate.te
+++ b/whitechapel/vendor/google/dumpstate.te
@@ -13,4 +13,4 @@ allow dumpstate modem_efs_file:dir getattr;
allow dumpstate modem_img_file:dir getattr;
allow dumpstate modem_userdata_file:dir getattr;
allow dumpstate fuse:dir search;
-
+allow dumpstate rlsservice:binder call; \ No newline at end of file
diff --git a/whitechapel/vendor/google/rlsservice.te b/whitechapel/vendor/google/rlsservice.te
index 4332495..0705e5d 100644
--- a/whitechapel/vendor/google/rlsservice.te
+++ b/whitechapel/vendor/google/rlsservice.te
@@ -36,3 +36,7 @@ allow rlsservice apex_info_file:file r_file_perms;
# Allow read camera property
get_prop(rlsservice, vendor_camera_prop);
+
+# Allow rlsservice bugreport generation
+allow rlsservice dumpstate:fd use;
+allow rlsservice dumpstate:fifo_file write; \ No newline at end of file