commit | 83515a522f8bee76982e3e361c5ad7cf6d95b531 | [log] [tgz] |
---|---|---|
author | Tim Zimmermann <tim@linux4.de> | Sun Oct 11 15:56:51 2020 +0200 |
committer | Tim Zimmermann <tim@linux4.de> | Fri Dec 18 07:15:32 2020 +0100 |
tree | cdf5dfc2df6f3422a42e39ea97da4605e3e9f344 | |
parent | 54b028bf42d44a4c89f402e53848950aaa469feb [diff] |
sepolicy: address denials on lte variant Change-Id: Id5d0278ebb9d4d750092ec514701c2022feac82c
diff --git a/sepolicy/vendor/init.te b/sepolicy/vendor/init.te index e5de48a..42bdb2d 100644 --- a/sepolicy/vendor/init.te +++ b/sepolicy/vendor/init.te
@@ -7,3 +7,5 @@ allow init tmpfs:lnk_file create; allow init kernel:system module_request; + +allow init socket_device:sock_file { create setattr unlink };
diff --git a/sepolicy/vendor/netd.te b/sepolicy/vendor/netd.te index 49157a7..c558dfd 100644 --- a/sepolicy/vendor/netd.te +++ b/sepolicy/vendor/netd.te
@@ -1,3 +1,5 @@ # netd.te allow netd sysfs_net_mtu_writable:file rw_file_perms; + +allow netd self:capability sys_module;