Skip to content
Snippets Groups Projects
Commit 35e41610 authored by Nick Kralevich's avatar Nick Kralevich Committed by Android Git Automerger
Browse files

am 37339c76: fix mediaserver selinux denials.

* commit '37339c76':
  fix mediaserver selinux denials.
parents e58a42f8 37339c76
No related branches found
No related tags found
No related merge requests found
...@@ -34,3 +34,6 @@ allow drmserver apk_data_file:dir rw_dir_perms; ...@@ -34,3 +34,6 @@ allow drmserver apk_data_file:dir rw_dir_perms;
type_transition drmserver apk_data_file:sock_file drmserver_socket; type_transition drmserver apk_data_file:sock_file drmserver_socket;
allow drmserver drmserver_socket:sock_file create_file_perms; allow drmserver drmserver_socket:sock_file create_file_perms;
allow drmserver tee:unix_stream_socket connectto; allow drmserver tee:unix_stream_socket connectto;
# After taking a video, drmserver looks at the video file.
r_dir_file(drmserver, media_rw_data_file)
...@@ -24,6 +24,7 @@ allow mediaserver app_data_file:file rw_file_perms; ...@@ -24,6 +24,7 @@ allow mediaserver app_data_file:file rw_file_perms;
allow mediaserver platform_app_data_file:file { getattr read }; allow mediaserver platform_app_data_file:file { getattr read };
allow mediaserver sdcard_type:file write; allow mediaserver sdcard_type:file write;
allow mediaserver graphics_device:chr_file rw_file_perms; allow mediaserver graphics_device:chr_file rw_file_perms;
allow mediaserver video_device:dir r_dir_perms;
allow mediaserver video_device:chr_file rw_file_perms; allow mediaserver video_device:chr_file rw_file_perms;
allow mediaserver audio_device:dir r_dir_perms; allow mediaserver audio_device:dir r_dir_perms;
allow mediaserver qemu_device:chr_file rw_file_perms; allow mediaserver qemu_device:chr_file rw_file_perms;
...@@ -47,8 +48,8 @@ allow mediaserver rpmsg_device:chr_file rw_file_perms; ...@@ -47,8 +48,8 @@ allow mediaserver rpmsg_device:chr_file rw_file_perms;
allow mediaserver system_server:fifo_file r_file_perms; allow mediaserver system_server:fifo_file r_file_perms;
# Camera data # Camera data
allow mediaserver camera_data_file:dir r_dir_perms; r_dir_file(mediaserver, camera_data_file)
allow mediaserver camera_data_file:file r_file_perms; r_dir_file(mediaserver, media_rw_data_file)
# Grant access to audio files to mediaserver # Grant access to audio files to mediaserver
allow mediaserver audio_data_file:dir ra_dir_perms; allow mediaserver audio_data_file:dir ra_dir_perms;
......
...@@ -21,6 +21,7 @@ allow surfaceflinger graphics_device:dir search; ...@@ -21,6 +21,7 @@ allow surfaceflinger graphics_device:dir search;
allow surfaceflinger graphics_device:chr_file rw_file_perms; allow surfaceflinger graphics_device:chr_file rw_file_perms;
# Access /dev/video1. # Access /dev/video1.
allow surfaceflinger video_device:dir r_dir_perms;
allow surfaceflinger video_device:chr_file rw_file_perms; allow surfaceflinger video_device:chr_file rw_file_perms;
# Create and use netlink kobject uevent sockets. # Create and use netlink kobject uevent sockets.
......
...@@ -132,6 +132,7 @@ allow system_server input_device:chr_file rw_file_perms; ...@@ -132,6 +132,7 @@ allow system_server input_device:chr_file rw_file_perms;
allow system_server tty_device:chr_file rw_file_perms; allow system_server tty_device:chr_file rw_file_perms;
allow system_server urandom_device:chr_file rw_file_perms; allow system_server urandom_device:chr_file rw_file_perms;
allow system_server usbaccessory_device:chr_file rw_file_perms; allow system_server usbaccessory_device:chr_file rw_file_perms;
allow system_server video_device:dir r_dir_perms;
allow system_server video_device:chr_file rw_file_perms; allow system_server video_device:chr_file rw_file_perms;
allow system_server qemu_device:chr_file rw_file_perms; allow system_server qemu_device:chr_file rw_file_perms;
allow system_server adbd_socket:sock_file rw_file_perms; allow system_server adbd_socket:sock_file rw_file_perms;
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment