From 0a3337595dcc9f432139790baef97dc5b0863094 Mon Sep 17 00:00:00 2001 From: Ruchi Kandoi <kandoiruchi@google.com> Date: Tue, 29 Apr 2014 19:07:31 -0700 Subject: [PATCH] ueventd: Adds permission to ueventd to access sysfs file Need this for changing max_cpufreq for the low power mode. Denials: type=1400 audit(1398818907.151:48): avc: denied { relabelfrom } for pid=129 comm="ueventd" name="scaling_max_freq" dev="sysfs" ino=19866 scontext=u:r:ueventd:s0 tcontext=u:object_r:sysfs:s0 tclass=file type=1400 audit(118521.050:11): avc: denied { setattr } for pid=130 comm="ueventd" name="scaling_min_freq" dev="sysfs" ino=9178 scontext=u:r:ueventd:s0 tcontext=u:object_r:sysfs_devices_system_cpu:s0 tclass=file Change required for Change-Id: Ibe0b4aaf3db555ed48e89a7fcd0c5fd3a18cf233 Change-Id: I93feee65b1535ac048acf3bc7fba9f5d1bdb2bd2 Signed-off-by: Ruchi Kandoi <kandoiruchi@google.com> --- ueventd.te | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/ueventd.te b/ueventd.te index e80fa32b8..66e70e874 100644 --- a/ueventd.te +++ b/ueventd.te @@ -12,8 +12,9 @@ allow ueventd device:file create_file_perms; allow ueventd device:chr_file rw_file_perms; allow ueventd sysfs:file rw_file_perms; allow ueventd sysfs:file setattr; +allow ueventd sysfs:file relabelfrom; allow ueventd sysfs_type:file { relabelfrom relabelto }; -allow ueventd sysfs_devices_system_cpu:file rw_file_perms; +allow ueventd sysfs_devices_system_cpu:file {rw_file_perms setattr}; allow ueventd tmpfs:chr_file rw_file_perms; allow ueventd dev_type:dir create_dir_perms; allow ueventd dev_type:lnk_file { create unlink }; -- GitLab