Allow virtualizationservice to check parent dir am: a9d70d7ba8 am: bd6d03f58b
Original change: https://android-review.googlesource.com/c/platform/system/sepolicy/+/2967573
Change-Id: Ia16c535554a6cf4de48111a83d70cc9da9b31d28
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
diff --git a/private/virtualizationservice.te b/private/virtualizationservice.te
index fcc7304..0a9ff8b 100644
--- a/private/virtualizationservice.te
+++ b/private/virtualizationservice.te
@@ -59,8 +59,9 @@
virtualizationservice_use(virtualizationservice)
# Allow virtualizationservice to read and write in the apex data directory
-# /data/misc/apexdata/com.android.virt
-allow virtualizationservice apex_module_data_file:dir search;
+# /data/misc/apexdata/com.android.virt. Also allow checking of the parent directory
+# (needed for SQLite database creation).
+allow virtualizationservice apex_module_data_file:dir { search getattr };
allow virtualizationservice apex_virt_data_file:dir create_dir_perms;
allow virtualizationservice apex_virt_data_file:file create_file_perms;