diff options
author | Bruno Martins <bgcngm@gmail.com> | 2016-08-18 11:08:38 +0100 |
---|---|---|
committer | Cosme Domínguez Díaz <cosme.ddiaz@gmail.com> | 2018-03-16 23:05:21 +0100 |
commit | b7f997f7ca7c1e9cae4e80b0c71b0cfacf62b27f (patch) | |
tree | f64f6b9db532f1cbdf8b898b710c597f8cf04c29 | |
parent | 3bd9ecea950bad249721a4814dd8651a24dbfdc0 (diff) |
sepolicy: Cleanup permissions
* Remove unneeded permissions
Change-Id: Ie52577eb3cf06e3adb4be9e40016407e451e604d
-rw-r--r-- | sepolicy/init.te | 17 | ||||
-rw-r--r-- | sepolicy/kernel.te | 1 |
2 files changed, 0 insertions, 18 deletions
diff --git a/sepolicy/init.te b/sepolicy/init.te deleted file mode 100644 index 075823c..0000000 --- a/sepolicy/init.te +++ /dev/null @@ -1,17 +0,0 @@ -allow init socket_device:sock_file { create unlink setattr }; -allow init proc_dirty_ratio:file write; -allow init vfat:dir mounton; - -allow init block_device:lnk_file relabelfrom; - -allow init { cache_block_device misc_block_device frp_block_device userdata_block_device rpmb_device dip_device recovery_block_device mba_debug_dev modem_efs_partition_device gpt_block_device persist_block_device }:lnk_file relabelto; - -allow init init:socket { create bind read }; -allow init init:capability net_bind_service; - -allow init { ssd_device rpmb_device modem_efs_partition_device }:blk_file write; - -allow init qti_debugfs:file write; - -allow init { tee_device diag_device }:chr_file { write read open ioctl }; -allow init ion_device:chr_file { read open ioctl }; diff --git a/sepolicy/kernel.te b/sepolicy/kernel.te deleted file mode 100644 index bd8c7b7..0000000 --- a/sepolicy/kernel.te +++ /dev/null @@ -1 +0,0 @@ -allow kernel tmpfs:dir search; |