Skip to content
Snippets Groups Projects
Commit 53cde700 authored by Stephen Smalley's avatar Stephen Smalley
Browse files

Report graphics_device accesses by system_server or mediaserver.


See if we can remove these allow rules by auditing any granting
of these permissions.  These rules may be a legacy of older Android
or some board where the gpu device lived under /dev/graphics too.

Change-Id: I5c5d99ca97402de5196d9b6dfd249294f4d95baa
Signed-off-by: default avatarStephen Smalley <sds@tycho.nsa.gov>
parent 91a4f8d4
No related branches found
No related tags found
No related merge requests found
......@@ -24,6 +24,7 @@ allow mediaserver app_data_file:dir search;
allow mediaserver app_data_file:file rw_file_perms;
allow mediaserver sdcard_type:file write;
allow mediaserver { gpu_device graphics_device }:chr_file rw_file_perms;
auditallow mediaserver graphics_device:chr_file rw_file_perms;
allow mediaserver video_device:dir r_dir_perms;
allow mediaserver video_device:chr_file rw_file_perms;
allow mediaserver audio_device:dir r_dir_perms;
......
......@@ -152,6 +152,7 @@ allow system_server alarm_device:chr_file rw_file_perms;
allow system_server gpu_device:chr_file rw_file_perms;
allow system_server graphics_device:dir search;
allow system_server graphics_device:chr_file rw_file_perms;
auditallow system_server graphics_device:chr_file rw_file_perms;
allow system_server iio_device:chr_file rw_file_perms;
allow system_server input_device:dir r_dir_perms;
allow system_server input_device:chr_file rw_file_perms;
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment