From ef907713b74820e157cf46be7dd6454ca1d83a9a Mon Sep 17 00:00:00 2001
From: Pawit Pornkitprasan
Date: Thu, 14 Nov 2013 10:46:26 +0700
Subject: [PATCH] sepolicy: allow vold to create files on external sdcard
This is required for ASEC support. Vold can already create and
access directories, but do not yet have the permission for files.
Change-Id: I5082bbff692e5dc53c7000e4b3a293e42d33f901
---
sepolicy/sepolicy.mk | 1 +
sepolicy/vold.te | 2 ++
2 files changed, 3 insertions(+)
create mode 100644 sepolicy/vold.te
diff --git a/sepolicy/sepolicy.mk b/sepolicy/sepolicy.mk
index 26d2caab..16a0e796 100644
--- a/sepolicy/sepolicy.mk
+++ b/sepolicy/sepolicy.mk
@@ -13,4 +13,5 @@ BOARD_SEPOLICY_UNION += \
genfs_contexts \
installd.te \
seapp_contexts \
+ vold.te \
mac_permissions.xml
diff --git a/sepolicy/vold.te b/sepolicy/vold.te
new file mode 100644
index 00000000..24514422
--- /dev/null
+++ b/sepolicy/vold.te
@@ -0,0 +1,2 @@
+# Allow vold to manage ASEC
+allow vold sdcard_external:file create_file_perms;