replicant-vendor_replicant/sepolicy
codeworkx b7c8dec762 cm: sepolicy: allow platform apps to crop user images
Needed for gallery3d when setting contact pics

avc: denied { write } for comm=4173796E635461736B202334
path="/data/data/com.android.settings/cache/CropEditUserPhoto.jpg" dev="mmcblk0p50" ino=65849
scontext=u:r:platform_app:s0:c512,c768 tcontext=u:object_r:system_app_data_file:s0 tclass=file
permissive=0

03-05 13:07:40.741  22060-22207/com.android.gallery3d W/System.err﹕ java.io.IOException: write
failed: EACCES (Permission denied)

Change-Id: Iaa7f75abfd41c86e1a321d5f35b950f9dc7eb930
2016-03-16 15:48:15 -07:00
..
qcom sepolicy: Add perfprofd with set_prop macro 2016-01-12 17:21:32 -08:00
app.te Grant platform apps access to /mnt/media_rw with sdcard_posix label 2016-01-24 14:39:42 -08:00
auditd.te selinux: Add rules for the audit daemon 2014-11-09 17:20:54 +00:00
bootanim.te sepolicy: Apps need to read themed resources 2015-01-14 15:55:41 +00:00
domain.te sepolicy: Remove some denials 2015-11-16 19:46:00 -08:00
drmserver.te sepolicy: Let drmserver scan themes 2015-01-25 11:02:24 -08:00
file_contexts sepolicy: label exfat and ntfs mkfs executables 2015-12-29 21:51:32 +01:00
file.te cm: sepolicy: Create standard policy for LiveDisplay 2015-09-15 15:31:19 -07:00
fsck_untrusted.te cm: sepolicy: fix denials for external storage 2016-01-01 17:30:27 +01:00
genfs_contexts cm: sepolicy: fix denials for external storage 2016-01-01 17:30:27 +01:00
healthd.te selinux: Fix healthd's access to /dev nodes 2014-11-27 22:57:21 +00:00
hostapd.te vendor: add policies for netd 2014-11-29 23:33:52 -08:00
init.te sepolicy: Add permission for formatting user/cache partition 2015-12-16 10:41:51 -08:00
installd.te
livedisplay.te cm: sepolicy: Create standard policy for LiveDisplay 2015-09-15 15:31:19 -07:00
mac_permissions.xml sepolicy: Allow CMUpdater/uncrypt access to recovery_cache_file 2015-02-21 17:21:47 -05:00
mediaserver.te sepolicy: Apps need to read themed resources 2015-01-14 15:55:41 +00:00
mkfs.te sepolicy: Add domain for mkfs binaries 2015-12-16 10:40:28 -08:00
netd.te vendor: add policies for netd 2014-11-29 23:33:52 -08:00
platform_app.te cm: sepolicy: allow platform apps to crop user images 2016-03-16 15:48:15 -07:00
property_contexts SELinux: Use custom ADB over network property 2015-12-16 11:01:50 -08:00
property.te sepolicy: allow userinit to set its property 2015-02-09 21:03:35 +00:00
recovery.te recovery: Add new rule for sys.usb.ffs.ready 2016-02-23 16:28:56 -08:00
seapp_contexts sepolicy: Allow CMUpdater/uncrypt access to recovery_cache_file 2015-02-21 17:21:47 -05:00
sepolicy.mk sepolicy: remove BOARD_SEPOLICY_UNION 2015-10-07 12:49:00 -07:00
service_contexts Themes: Refactor themes to CMSDK [3/6] 2016-03-01 09:57:15 -08:00
service.te Themes: Refactor themes to CMSDK [3/6] 2016-03-01 09:57:15 -08:00
su.te cm: sepolicy: allow kernel to read storage 2016-02-20 14:26:41 -08:00
sysinit.te sepolicy: Permissions for userinit 2015-03-17 12:12:59 +00:00
system_app.te sepolicy: Allow system app to set boot anim property 2015-09-21 18:16:18 -07:00
system_server.te sepolicy: Allow system server and uncrypt access pipe 2016-02-09 13:24:46 -08:00
system.te cm: Remove duplicate SEPolicy items 2015-10-31 02:08:33 -07:00
ueventd.te
uncrypt.te sepolicy: Allow system server and uncrypt access pipe 2016-02-09 13:24:46 -08:00
userinit.te sepolicy: Permissions for userinit 2015-03-17 12:12:59 +00:00
vold.te sepolicy: Allow minivold execute_no_trans 2016-01-02 02:07:18 -08:00
zygote.te cm: Fix a few denials 2015-09-19 22:49:20 -07:00