summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
Diffstat (limited to 'sepolicy/init.te')
-rw-r--r--sepolicy/init.te21
1 files changed, 2 insertions, 19 deletions
diff --git a/sepolicy/init.te b/sepolicy/init.te
index 8a1581e..2329198 100644
--- a/sepolicy/init.te
+++ b/sepolicy/init.te
@@ -1,28 +1,11 @@
1#For holding a wake_lock in init.rc 1#For loading modules via init.rc (ex: wifi)
2wakelock_use(init)
3
4#For loading modules via init.rc
5allow init self:capability sys_module; 2allow init self:capability sys_module;
6
7#Create symlinks for storage 3#Create symlinks for storage
8allow init tmpfs:lnk_file create_file_perms; 4allow init tmpfs:lnk_file create_file_perms;
9
10# Allow module insertion 5# Allow module insertion
11allow init vendor_file:system module_load; 6allow init vendor_file:system module_load;
12
13# Configfs 7# Configfs
14allow init configfs:file write; 8allow init configfs:file write;
15allow init configfs:lnk_file { create unlink } ; 9allow init configfs:lnk_file { create unlink } ;
16 10
17# For cgroups creating 11dontaudit init proc:file write;
18allow init cgroup:file create;
19
20# Access to /proc
21allow init proc:dir { add_name write };
22allow init proc:file create;
23
24# Access to /sys
25allow init sysfs:file create;
26allow init sysfs:dir add_name;
27
28dontaudit init self:capability dac_read_search;