diff --git a/vendor/hal_wifi_supplicant_default.te b/vendor/hal_wifi_supplicant_default.te index 1ff9ba2473a723901cd35f7b8e63d231f39aba4b..cca80947cf9dc2605787a3923a07d41a643c84d2 100644 --- a/vendor/hal_wifi_supplicant_default.te +++ b/vendor/hal_wifi_supplicant_default.te @@ -15,3 +15,11 @@ binder_call(hal_wifi_supplicant_default, wifi_keystore_service_server) # Write to security logs for audit. get_prop(hal_wifi_supplicant_default, device_logging_prop) + +# Devices upgrading to P may grant this permission in device-specific +# policy along with the data_between_core_and_vendor_violators +# attribute needed for an exemption. However, devices that launch with +# P should use /data/vendor/wifi, which is already granted in core +# policy. This is dontaudited here to avoid conditional +# device-specific behavior in wpa_supplicant. +dontaudit hal_wifi_supplicant_default wifi_data_file:dir search;