Allow init to mkdir inside /data/gsi.
Bug: 133435561
Test: adb shell gsi_tool install
Change-Id: Iaa610c72d8098e157bb89e321624369f86f4ea19
diff --git a/private/gsid.te b/private/gsid.te
index 5dcf746..1a35a4b 100644
--- a/private/gsid.te
+++ b/private/gsid.te
@@ -118,6 +118,7 @@
neverallow {
domain
-gsid
+ -init
} gsi_data_file:dir ~{ open create read getattr setattr search relabelto ioctl };
neverallow {
diff --git a/public/init.te b/public/init.te
index 86e0d32..adeaeb0 100644
--- a/public/init.te
+++ b/public/init.te
@@ -170,7 +170,6 @@
file_type
-app_data_file
-exec_type
- -gsi_data_file
-iorapd_data_file
-keystore_data_file
-misc_logd_file