diff --git a/public/hal_camera.te b/public/hal_camera.te index 3c15e85f935f3180816bda0f763ec79fa49b698b..413a057bc803f2fbf9430c254bfdf30f68eb5f8c 100644 --- a/public/hal_camera.te +++ b/public/hal_camera.te @@ -32,6 +32,5 @@ neverallow hal_camera { file_type fs_type }:file execute_no_trans; # hal_camera should never need network access. Disallow network sockets. neverallow hal_camera domain:{ tcp_socket udp_socket rawip_socket } *; -# Only camera HAL may directly access the camera and video hardware +# Only camera HAL may directly access the camera hardware neverallow { halserverdomain -hal_camera_server } camera_device:chr_file *; -neverallow { halserverdomain -coredomain -hal_camera_server } video_device:chr_file *;