allwinner_a64/android/device/softwinner/common/sepolicy/vendor/rild.te
2018-08-08 17:48:24 +08:00

67 lines
2.7 KiB
Text

set_prop(rild, system_prop)
set_prop(rild, net_radio_prop)
allow rild sysfs:file write;
allow rild usb_device:dir r_dir_perms;
allow rild usb_device:chr_file {open read write ioctl relabelfrom};
allow rild ppp_exec:file {getattr execute read open execute_no_trans};
allow rild ppp_device:chr_file rw_file_perms;
allow rild kernel:dir {search getattr open read};
allow rild kernel:file{open read};
allow rild init:dir {search getattr};
allow rild init:file {open read};
allow rild init:lnk_file {read};
allow rild ueventd:dir {search getattr};
allow rild ueventd:file {open read};
allow rild ueventd:lnk_file {open read};
allow rild ueventd:chr_file { relabelfrom };
allow rild sdcardd:dir {read search getattr};
allow rild logd:dir {read search getattr};
allow rild lmkd:dir {search getattr};
allow rild lmkd:file {open read};
allow rild healthd:dir {search getattr};
allow rild healthd:file {open read};
allow rild servicemanager:dir {search getattr};
allow rild servicemanager:file{open read};
allow rild vold:dir {search getattr};
allow rild vold:file {open read};
allow rild shell:dir {search getattr};
allow rild shell:file {open read};
allow rild netd:dir {search getattr};
allow rild netd:file{open read};
allow rild radio:dir {search getattr};
allow rild radio:file {open read};
allow rild system_server:dir {search getattr};
allow rild system_app:dir {search getattr};
allow rild system_app:file {read open};
allow rild platform_app:dir {search getattr};
allow rild platform_app:file {open read};
allow rild untrusted_app:dir {search getattr};
allow rild untrusted_app:file rw_file_perms;
allow rild surfaceflinger:dir {search getattr};
allow rild surfaceflinger:file {open read};
allow rild logd:file {open read};
allow rild sdcardd:file {open read};
allow rild drmserver:dir {search getattr};
allow rild drmserver:file{open read};
allow rild mediaserver:dir {search getattr};
allow rild mediaserver:file {open read};
allow rild installd:dir {search getattr};
allow rild installd:file {open read};
allow rild keystore:dir {search getattr};
allow rild keystore:file {open read};
allow rild zygote:dir {search getattr};
allow rild zygote:file {open read};
allow rild system_server:file {open read};
allow rild self:capability { dac_override setgid setuid fowner chown sys_module};
allow rild rootfs:file {getattr execute execute_no_trans};
allow rild kernel:lnk_file read;
allow rild toolbox_exec:file { execute getattr read open execute_no_trans};
allow rild system_file:file execute_no_trans;
allow rild vendor_file:file execute_no_trans;
allow rild vendor_toolbox_exec:file execute_no_trans;
allow rild rootfs:dir read;
allow rild rootfs:dir open;
allow rild vendor_shell_exec:file execute_no_trans;