summaryrefslogtreecommitdiff
Diffstat
-rw-r--r--core_amlogic.mk49
-rw-r--r--factory.mk16
-rw-r--r--products/mbox/init.amlogic.rc2
-rw-r--r--products/mbox/upgrade_4.9/aml_upgrade_package_AB.conf1
-rw-r--r--products/mbox/upgrade_4.9/aml_upgrade_package_AB_enc.conf6
-rw-r--r--products/tv/init.amlogic.rc2
-rw-r--r--recovery/check/Android.mk4
-rw-r--r--recovery/recovery_extra/Android.mk4
-rw-r--r--recovery/ui/Android.mk4
-rw-r--r--recovery/updater_extra/Android.mk4
-rw-r--r--sepolicy/e2fs.te7
-rw-r--r--sepolicy/file.te2
-rw-r--r--sepolicy/file_contexts4
-rw-r--r--sepolicy/hal_cas_default.te2
-rw-r--r--sepolicy/hal_memtrack_default.te11
-rw-r--r--sepolicy/logd.te1
-rw-r--r--sepolicy/mediaprovider.te1
-rw-r--r--sepolicy/recovery.te16
-rw-r--r--sepolicy/system_app.te12
-rw-r--r--sepolicy/system_server.te4
-rw-r--r--sepolicy/untrusted_app.te1
-rw-r--r--sepolicy/untrusted_app_25.te1
-rw-r--r--sepolicy/zygote.te2
-rw-r--r--vendor-overlay/Android.mk18
-rw-r--r--vendor-overlay/AndroidManifest.xml6
-rw-r--r--vendor-overlay/res/values/config.xml5
-rw-r--r--vndk/Android.mk50
-rw-r--r--wifi.mk8
28 files changed, 171 insertions, 72 deletions
diff --git a/sepolicy/recovery.te b/sepolicy/recovery.te
index 033ac7a..3be1941 100644
--- a/sepolicy/recovery.te
+++ b/sepolicy/recovery.te
@@ -26,14 +26,26 @@ allow recovery recovery:capability { net_admin };
allow recovery aml_display_prop:file {open read getattr};
allow recovery uboot_prop:file {open read getattr};
-allow recovery update_data_file:file rw_file_perms;
-allow recovery update_data_file:dir { search read write open };
+allow recovery self:capability2 syslog;
+allow recovery sysfs_fs_ext4_features:dir search;
+allow recovery sysfs_fs_ext4_features:file read;
+
+#allow recovery update_data_file:file rw_file_perms;
+#allow recovery update_data_file:dir { search read write open };
allow recovery graphics_device:dir {search};
allow recovery graphics_device:chr_file {open read write ioctl};
allow shell rootfs:file { entrypoint execute getattr open read };
+allow recovery bcmdl_prop:file { getattr open };
+allow recovery media_prop:file { getattr open };
+allow recovery sysfs_audio_cap:file read;
+allow recovery sysfs_video:file { open read write };
+allow recovery tv_config_prop:file { getattr open };
+allow recovery tv_prop:file { getattr open };
+allow recovery wifi_prop:file { getattr open };
+
allow shell tmpfs:file {open read getattr};
allow shell sysfs:file { read open };
allow shell rootfs:file {execute_no_trans};