summaryrefslogtreecommitdiff
path: root/common/sepolicy/recovery.te (plain)
blob: e55927065227ca8be1a09902d85a5bf84a865a55
1recovery_only(`
2
3 allow recovery uboot_prop:property_service set;
4 allow recovery rootfs:dir create_dir_perms;
5 allow recovery sysfs:dir mounton;
6 #allow recovery debugfs:file r_file_perms;
7
8 allow recovery vfat:dir create_dir_perms;
9 allow recovery vfat:file create_file_perms;
10
11 #allow recovery ppp_system_file:file {create_file_perms relabelfrom relabelto};
12 #allow recovery ppp_system_file:dir {create_dir_perms relabelfrom relabelto};
13
14# allow recovery env_device:chr_file rw_file_perms;
15# allow recovery input_device:chr_file write;
16 allow recovery property_data_file:dir { search };
17 allow recovery device:dir rw_dir_perms;
18# allow recovery bootloader_device:chr_file rw_file_perms;
19# allow recovery defendkey_device:chr_file rw_file_perms;
20 allow recovery dtb_device:chr_file { open read write };
21 allow recovery aml_display_prop:property_service set;
22# allow recovery kmsg_device:chr_file rw_file_perms;
23 allow recovery recovery:capability { net_admin };
24# allow recovery recovery:netlink_kobject_uevent_socket { create bind setopt read };
25 allow recovery aml_display_prop:file {open read getattr};
26 allow recovery uboot_prop:file {open read getattr};
27 allow recovery sysfs_xbmc:file {open read write};
28 allow recovery update_data_file:file rw_file_perms;
29 allow recovery update_data_file:dir { search read write open };
30
31 allow shell tmpfs:file {open read getattr};
32 allow shell sysfs:file {read};
33 allow shell rootfs:file {execute_no_trans};
34')
35