diff --git a/public/domain.te b/public/domain.te index 8a42336fb515da602f92da3f77c736b079b047e8..5cda0ec7af5320c9a1a6c719d42232d17420959a 100644 --- a/public/domain.te +++ b/public/domain.te @@ -67,7 +67,12 @@ allow domain null_device:chr_file rw_file_perms; allow domain zero_device:chr_file rw_file_perms; allow domain ashmem_device:chr_file rw_file_perms; # /dev/binder can be accessed by non-vendor domains and by apps -allow { coredomain appdomain -hwservicemanager } binder_device:chr_file rw_file_perms; +allow { + coredomain + appdomain + binder_in_vendor_violators # TODO(b/35870313): Remove once all violations are gone + -hwservicemanager +} binder_device:chr_file rw_file_perms; # Devices which are not full TREBLE have fewer restrictions on access to /dev/binder not_full_treble(`allow { domain -hwservicemanager -vndservicemanager } binder_device:chr_file rw_file_perms;') allow { domain -servicemanager -vndservicemanager } hwbinder_device:chr_file rw_file_perms;