nougat_device_meizu_m2note/sepolicy/nvram_daemon.te

29 lines
1.1 KiB
Plaintext

type nvram_daemon_exec, exec_type, file_type;
type nvram_daemon, domain, domain_deprecated;
init_daemon_domain(nvram_daemon)
allow nvram_daemon self:capability { fowner dac_override dac_read_search chown fsetid };
allow nvram_daemon nvram_device:blk_file rw_file_perms;
allow nvram_daemon nvdata_device:blk_file rw_file_perms;
allow nvram_daemon nvdata_file:dir create_dir_perms;
allow nvram_daemon nvdata_file:file create_file_perms;
allow nvram_daemon nvdata_file:lnk_file r_file_perms;
allow nvram_daemon shell_exec:file { read execute open execute_no_trans getattr };
allow nvram_daemon als_ps_device:chr_file r_file_perms;
allow nvram_daemon mtk-adc-cali_device:chr_file rw_file_perms;
allow nvram_daemon gsensor_device:chr_file r_file_perms;
allow nvram_daemon msensor_device:chr_file r_file_perms;
allow nvram_daemon gyroscope_device:chr_file r_file_perms;
allow nvram_daemon toolbox_exec:file rx_file_perms;
allow nvram_daemon proinfo_device:blk_file rw_file_perms;
set_prop(nvram_daemon, nvram_prop)
set_prop(nvram_daemon, wmt_prop)
allow nvram_daemon block_device:dir search;
# boot_mode
allow nvram_daemon sysfs_boot_mode:file r_file_perms;