summaryrefslogtreecommitdiff
authorTellen Yu <tellen.yu@amlogic.com>2017-10-30 06:27:42 (GMT)
committer Gerrit Code Review <gituser@scgit.amlogic.com>2017-10-30 06:27:42 (GMT)
commitfbd2c3c34c6d74862187cd5f1d0732cfda929b0b (patch)
treef0a4dae91edcef83f2eba9d47ffeab0a2c1a1cd1
parent31cb9101538f7b02a1980b99a19576f5f976b707 (diff)
parent262e8964eeb3ceac491c84daf780a68fd2a8a95b (diff)
downloadamlogic-o-fbd2c3c34c6d74862187cd5f1d0732cfda929b0b.zip
amlogic-o-fbd2c3c34c6d74862187cd5f1d0732cfda929b0b.tar.gz
amlogic-o-fbd2c3c34c6d74862187cd5f1d0732cfda929b0b.tar.bz2
Merge "Device: change system_app.te for FileListManager and add droidmount binder servic[5/5]" into o-amlogic
Diffstat
-rw-r--r--common/sepolicy/service_contexts1
-rw-r--r--common/sepolicy/system_app.te4
2 files changed, 4 insertions, 1 deletions
diff --git a/common/sepolicy/service_contexts b/common/sepolicy/service_contexts
index 6c43c88..9617d41 100644
--- a/common/sepolicy/service_contexts
+++ b/common/sepolicy/service_contexts
@@ -7,3 +7,4 @@ tvservice u:object_r:tvserver_service:s0
media.screenmediasource u:object_r:screenmediasource_service:s0
tee_supplicant u:object_r:tee_service:s0
tv_remote u:object_r:tv_remote_service:s0
+droidmount u:object_r:mount_service:s0
diff --git a/common/sepolicy/system_app.te b/common/sepolicy/system_app.te
index d48a6ec..c24b45c 100644
--- a/common/sepolicy/system_app.te
+++ b/common/sepolicy/system_app.te
@@ -24,7 +24,7 @@ allow system_app unlabeled:file { lock open read write getattr };
# /cache_file for dvb app creat update.zip file at /cache dir
allow system_app cache_file:dir {create_dir_perms create_file_perms rw_file_perms};
-allow system_app cache_file:file {create_file_perms rw_file_perms};
+allow system_app cache_file:file {create_file_perms rw_file_perms getattr};
allow system_app log_file:dir { search read open getattr };
allow system_app log_file:file { read open getattr };
@@ -57,3 +57,5 @@ allow system_app exfat:file create_file_perms;
allow system_app ntfs:dir create_dir_perms;
allow system_app ntfs:file create_file_perms;
+
+allow system_app mnt_media_rw_file:dir r_dir_perms;