sepolicy: cleanup

This commit is contained in:
Mister Oyster 2017-08-30 16:41:54 +02:00
parent 78ddd99bbf
commit c298ffcbfb
10 changed files with 29 additions and 36 deletions

View File

@ -1 +0,0 @@
allow bootanim sysfs_devinfo:file { open read };

View File

@ -1,31 +1,31 @@
# Services
/system/bin/6620_launcher u:object_r:conn_launcher_exec:s0
/(system|system\/vendor|vendor)bin/ccci_fsd u:object_r:ccci_fsd_exec:s0
/(system|system\/vendor|vendor)bin/ccci_mdinit u:object_r:ccci_mdinit_exec:s0
/(system|system\/vendor|vendor)bin/md_ctrl u:object_r:md_ctrl_exec:s0
/(system|system\/vendor|vendor)bin/fuelgauged u:object_r:fuelgauged_exec:s0
/(system|system\/vendor|vendor)bin/gsm0710muxd u:object_r:gsm0710muxd_exec:s0
/(system|system\/vendor|vendor)xbin/mnld u:object_r:mnld_exec:s0
/(system|system\/vendor|vendor)bin/muxreport u:object_r:muxreport_exec:s0
/(system|system\/vendor|vendor)bin/msensord u:object_r:msensord_exec:s0
/(system|system\/vendor|vendor)bin/akmd09911 u:object_r:akmd09911_exec:s0
/(system|system\/vendor|vendor)bin/mtk_agpsd u:object_r:mtk_agpsd_exec:s0
/(system|system\/vendor|vendor)bin/nvram_daemon u:object_r:nvram_daemon_exec:s0
/(system|system\/vendor|vendor)bin/pq u:object_r:pq_exec:s0
/(system|system\/vendor|vendor)bin/terservice u:object_r:terservice_exec:s0
/(system|system\/vendor|vendor)bin/thermal_manager u:object_r:thermal_manager_exec:s0
/(system|system\/vendor|vendor)bin/mtkrild u:object_r:ril-daemon-mtk_exec:s0
/(system|system\/vendor|vendor)bin/wifi2agps u:object_r:wifi2agps_exec:s0
/(system|system\/vendor|vendor)bin/wmt_loader u:object_r:wmt_loader_exec:s0
/(system|system\/vendor|vendor)bin/em_svr u:object_r:em_svr_exec:s0
/(system|system\/vendor|vendor)bin/kpoc_charger u:object_r:kpoc_charger_exec:s0
/(system|system\/vendor|vendor)/bin/6620_launcher u:object_r:conn_launcher_exec:s0
/(system|system\/vendor|vendor)/bin/ccci_fsd u:object_r:ccci_fsd_exec:s0
/(system|system\/vendor|vendor)/bin/ccci_mdinit u:object_r:ccci_mdinit_exec:s0
/(system|system\/vendor|vendor)/bin/md_ctrl u:object_r:md_ctrl_exec:s0
/(system|system\/vendor|vendor)/bin/fuelgauged u:object_r:fuelgauged_exec:s0
/(system|system\/vendor|vendor)/bin/gsm0710muxd u:object_r:gsm0710muxd_exec:s0
/(system|system\/vendor|vendor)/xbin/mnld u:object_r:mnld_exec:s0
/(system|system\/vendor|vendor)/bin/muxreport u:object_r:muxreport_exec:s0
/(system|system\/vendor|vendor)/bin/msensord u:object_r:msensord_exec:s0
/(system|system\/vendor|vendor)/bin/akmd09911 u:object_r:akmd09911_exec:s0
/(system|system\/vendor|vendor)/bin/mtk_agpsd u:object_r:mtk_agpsd_exec:s0
/(system|system\/vendor|vendor)/bin/nvram_daemon u:object_r:nvram_daemon_exec:s0
/(system|system\/vendor|vendor)/bin/pq u:object_r:pq_exec:s0
/(system|system\/vendor|vendor)/bin/terservice u:object_r:terservice_exec:s0
/(system|system\/vendor|vendor)/bin/thermal_manager u:object_r:thermal_manager_exec:s0
/(system|system\/vendor|vendor)/bin/mtkrild u:object_r:ril-daemon-mtk_exec:s0
/(system|system\/vendor|vendor)/bin/wifi2agps u:object_r:wifi2agps_exec:s0
/(system|system\/vendor|vendor)/bin/wmt_loader u:object_r:wmt_loader_exec:s0
/(system|system\/vendor|vendor)/bin/em_svr u:object_r:em_svr_exec:s0
/(system|system\/vendor|vendor)/bin/kpoc_charger u:object_r:kpoc_charger_exec:s0
# Meizupshelper
/(system|system\/vendor|vendor)bin/meizupshelper u:object_r:meizupshelper_exec:s0
/(system|system\/vendor|vendor)/bin/meizupshelper u:object_r:meizupshelper_exec:s0
# Meta mode
/(system|system\/vendor|vendor)bin/meta_tst u:object_r:meta_tst_exec:s0
/(system|system\/vendor|vendor)bin/factory u:object_r:factory_exec:s0
/(system|system\/vendor|vendor)/bin/meta_tst u:object_r:meta_tst_exec:s0
/(system|system\/vendor|vendor)/bin/factory u:object_r:factory_exec:s0
# Files from firmware/nv partitions
/protect_f(/.*)? u:object_r:protect_f_data_file:s0

View File

@ -1,3 +1,3 @@
allow fsck protect1_device:blk_file rw_file_perms;
allow fsck protect2_device:blk_file rw_file_perms;
allow fsck nvdata_device:blk_file rw_file_perms;
allow fsck protect1_device:blk_file rw_file_perms;
allow fsck protect2_device:blk_file rw_file_perms;
allow fsck nvdata_device:blk_file rw_file_perms;

View File

@ -7,7 +7,7 @@ allow mediacodec ccci_device:chr_file rw_file_perms;
allow mediacodec Vcodec_device:chr_file rw_file_perms;
allow mediacodec devmap_device:chr_file { ioctl r_file_perms };
allow mediacodec mtk_smi_device:chr_file { ioctl read open };
allow mediacodec proc:file { ioctl getattr open read };
allow mediacodec proc:file { getattr open read ioctl };
allow mediacodec sysfs:file { open read write };
allow mediacodec sysfs_devinfo:file { open read write };

View File

@ -1,4 +1,3 @@
allow platform_app sysfs_devinfo:file { open read };
# Guiext
allow platform_app guiext-server_service:service_manager find;

View File

@ -12,7 +12,7 @@ type audiohal_prop, property_type, mtk_property_type;
type ril_mux_report_case_prop, property_type, mtk_property_type;
type ril_msim_power_prop, property_type, mtk_property_type;
type ril_sim_inserted_status, property_type, mtk_property_type;
type vold_encryption_type_prop, property_type;
# mtk sn
type serial_number_prop, property_type, mtk_property_type;
type vold_encryption_type_prop, property_type;

View File

@ -20,7 +20,7 @@ sys.msim.power.slot0 u:object_r:ril_msim_power_prop:s0
sys.msim.power.slot1 u:object_r:ril_msim_power_prop:s0
sys.sim_inserted_status_0 u:object_r:ril_sim_inserted_status:s0
sys.sim_inserted_status_1 u:object_r:ril_sim_inserted_status:s0
vold.encryption.type u:object_r:vold_encryption_type_prop:s0
# Mtk sn
ro.serialno u:object_r:serial_number_prop:s0
vold.encryption.type u:object_r:vold_encryption_type_prop:s0

View File

@ -5,5 +5,3 @@ allow surfaceflinger guiext-server_service:service_manager { find add };
allow surfaceflinger debug_prop:property_service set;
allow surfaceflinger mtk_smi_device:chr_file { read write open ioctl };
allow surfaceflinger sysfs_devinfo:file { open read };

View File

@ -3,5 +3,3 @@ allow system_app perf_control_sysfs:file rw_file_perms;
allow system_app smartwake_sysfs:file rw_file_perms;
allow system_app em_svr:unix_stream_socket connectto;
allow system_app sysfs_devinfo:file { open read };

View File

@ -16,7 +16,6 @@ allow system_server smartwake_sysfs:file rw_file_perms;
# Wifi
allow system_server wmtWifi_device:chr_file w_file_perms;
allow system_server sysfs_devinfo:file { open read };
# Debugfs
allow system_server debugfs:dir r_file_perms;