3
0

galaxys2: refine sepolicies

Change-Id: Ifa7e56537af87f14a59e5c9b5f254073eea22a8f
This commit is contained in:
Daniel Hillenbrand 2013-08-11 18:12:03 +02:00
parent 2798599884
commit 4ce796517d
3 changed files with 16 additions and 9 deletions

View File

@ -38,6 +38,21 @@ on fs
mkdir /data/misc/radio 0775 radio system mkdir /data/misc/radio 0775 radio system
chmod 0770 /data/misc/wifi chmod 0770 /data/misc/wifi
# Restorecon
restorecon /efs/nv_data.bin
restorecon /efs/nv_data.bin.md5
restorecon /efs/.nv_core.bak
restorecon /efs/.nv_core.bak.md5
restorecon /efs/.nv_data.bak
restorecon /efs/.nv_data.bak.md5
restorecon /efs/.nv_state
restorecon /efs/bluetooth/bt_addr
restorecon /efs/FactoryApp/factorymode
restorecon /efs/FactoryApp/hw_ver
restorecon /efs/FactoryApp/keystr
restorecon /efs/FactoryApp/serial_no
restorecon /efs/imei/mps_code.dat
on post-fs-data on post-fs-data
# insmod kernel modules # insmod kernel modules
insmod /system/lib/modules/j4fs.ko insmod /system/lib/modules/j4fs.ko

View File

@ -15,11 +15,6 @@
/dev/block/mmcblk0p7 u:object_r:efs_block_device:s0 /dev/block/mmcblk0p7 u:object_r:efs_block_device:s0
/efs/imei/mps_code.dat u:object_r:radio_data_file:s0
/efs/nv_data.bin u:object_r:radio_data_file:s0
/efs/nv_data.bin.md5 u:object_r:radio_data_file:s0
/efs/upgaddr u:object_r:efs_file:s0
# Bluetooth # Bluetooth
/dev/ttySAC0 u:object_r:hci_attach_dev:s0 /dev/ttySAC0 u:object_r:hci_attach_dev:s0
/efs/bluetooth(/.*)? u:object_r:bluetooth_data_file:s0 /efs/bluetooth(/.*)? u:object_r:bluetooth_data_file:s0

View File

@ -3,8 +3,5 @@ allow rild self:netlink_route_socket { write };
allow rild self:netlink_kobject_uevent_socket { create bind read write }; allow rild self:netlink_kobject_uevent_socket { create bind read write };
allow rild radio_device:chr_file rw_file_perms; allow rild radio_device:chr_file rw_file_perms;
allow rild efs_block_device:blk_file rw_file_perms; allow rild efs_block_device:blk_file rw_file_perms;
allow rild efs_file:file { read open write setattr };
allow rild radio_data_file:file { read open write setattr };
allow rild efs_file:file { read open write getattr };