Files
Stricted 9a2030010d [WIP]start this selinux mess
* taken from https://github.com/lineage-geminipda/android_device_planet_geminipda

Change-Id: I80708a4650646ecd870b60217cafc0212aa2022e
(cherry picked from commit ce9dd0181db0cdeabb9edaf3781d74fb6645bb98)
2021-01-17 01:13:03 +00:00

25 lines
1.2 KiB
Plaintext

type kpoc_charger, domain, domain_deprecated;
type kpoc_charger_exec, exec_type, file_type;
init_daemon_domain(kpoc_charger)
allow kpoc_charger block_device:dir search;
allow kpoc_charger graphics_device:dir search;
allow kpoc_charger input_device:dir { open read search };
allow kpoc_charger input_device:chr_file { open read write ioctl };
allow kpoc_charger property_socket:sock_file write;
allow kpoc_charger self:capability sys_nice;
allow kpoc_charger self:capability net_admin;
allow kpoc_charger self:capability dac_override;
allow kpoc_charger self:netlink_kobject_uevent_socket { create bind read setopt };
allow kpoc_charger sysfs:file write;
allow kpoc_charger graphics_device:chr_file { read write ioctl open };
allow kpoc_charger kmsg_device:chr_file { write open };
allow kpoc_charger logo_block_device:blk_file { read open };
allow kpoc_charger rtc_device:chr_file { open read write };
allow kpoc_charger init:unix_stream_socket connectto;
allow healthd self:capability dac_override;
allow healthd app_data_file:file write;
allow healthd device:dir {open read write};
allow kpoc_charger self:capability sys_boot;
allow kpoc_charger alarm_device:chr_file write;