summaryrefslogtreecommitdiff
path: root/sepolicy/recovery.te (plain)
blob: 3be1941aae8d258262b70d9fb2b64f7723bf26be
1allow recovery aml_display_prop:property_service set;
2allow recovery input_device:chr_file write;
3allow recovery kmsg_device:chr_file { write open read };
4allow recovery self:netlink_kobject_uevent_socket { create setopt bind read };
5allow recovery sysfs_xbmc:file { read write open };
6allow recovery system_prop:property_service set;
7allow recovery self:capability net_admin;
8
9allow recovery uboot_prop:property_service set;
10allow recovery rootfs:dir create_dir_perms;
11allow recovery sysfs:dir mounton;
12
13allow recovery vfat:dir create_dir_perms;
14allow recovery vfat:file create_file_perms;
15
16allow recovery env_device:chr_file rw_file_perms;
17allow recovery input_device:chr_file write;
18allow recovery property_data_file:dir { search };
19allow recovery device:dir rw_dir_perms;
20allow recovery bootloader_device:chr_file rw_file_perms;
21allow recovery defendkey_device:chr_file rw_file_perms;
22allow recovery dtb_device:chr_file { open read write };
23allow recovery aml_display_prop:property_service set;
24allow recovery recovery:capability { net_admin };
25
26allow recovery aml_display_prop:file {open read getattr};
27allow recovery uboot_prop:file {open read getattr};
28
29allow recovery self:capability2 syslog;
30allow recovery sysfs_fs_ext4_features:dir search;
31allow recovery sysfs_fs_ext4_features:file read;
32
33#allow recovery update_data_file:file rw_file_perms;
34#allow recovery update_data_file:dir { search read write open };
35
36allow recovery graphics_device:dir {search};
37allow recovery graphics_device:chr_file {open read write ioctl};
38
39allow shell rootfs:file { entrypoint execute getattr open read };
40
41allow recovery bcmdl_prop:file { getattr open };
42allow recovery media_prop:file { getattr open };
43allow recovery sysfs_audio_cap:file read;
44allow recovery sysfs_video:file { open read write };
45allow recovery tv_config_prop:file { getattr open };
46allow recovery tv_prop:file { getattr open };
47allow recovery wifi_prop:file { getattr open };
48
49allow shell tmpfs:file {open read getattr};
50allow shell sysfs:file { read open };
51allow shell rootfs:file {execute_no_trans};
52