summaryrefslogtreecommitdiffstats
path: root/sepolicy
diff options
context:
space:
mode:
authorFrozenCow <frozencow@gmail.com>2016-01-11 23:10:47 +0100
committerGerrit Code Review <gerrit@cyanogenmod.org>2016-02-20 14:26:41 -0800
commitec0322e31b4b879af32459ce0c0e40a1170e1243 (patch)
tree61e43d84807f2a3d35b0d46e68d8b3536d9dc9c8 /sepolicy
parent4a2f567dc91e3551e9c724144040ce4ed4ff4005 (diff)
downloadvendor_replicant-ec0322e31b4b879af32459ce0c0e40a1170e1243.zip
vendor_replicant-ec0322e31b4b879af32459ce0c0e40a1170e1243.tar.gz
vendor_replicant-ec0322e31b4b879af32459ce0c0e40a1170e1243.tar.bz2
cm: sepolicy: allow kernel to read storage
This fixes issues where the kernel would need to read and write files from internal or external storage. More specifically, the kernel needs these rules for USB mass storage to work correctly. Change-Id: I8cb0307727bc0c464d5470e55275ad808e748ee0
Diffstat (limited to 'sepolicy')
-rw-r--r--sepolicy/su.te2
1 files changed, 2 insertions, 0 deletions
diff --git a/sepolicy/su.te b/sepolicy/su.te
index 9cd6345..473386b 100644
--- a/sepolicy/su.te
+++ b/sepolicy/su.te
@@ -64,4 +64,6 @@ userdebug_or_eng(`
allow system_app superuser_device:sock_file { read write create setattr unlink getattr };
allow system_app sudaemon:unix_stream_socket { connectto read write setopt ioctl };
allow system_app superuser_device:dir { create rw_dir_perms setattr unlink };
+
+ allow kernel sudaemon:fd { use };
')