From d823ca236f33504ad113f6d04c12892715fcf0c3 Mon Sep 17 00:00:00 2001 From: LuK1337 Date: Mon, 26 Sep 2016 16:46:16 +0200 Subject: [PATCH] sepolicy: Fix adbsecure_prop denials Change-Id: I78a5570f330e703b7f7ac2b34370a83bbb2a0d87 --- sepolicy/system_app.te | 3 +++ sepolicy/system_server.te | 2 ++ 2 files changed, 5 insertions(+) diff --git a/sepolicy/system_app.te b/sepolicy/system_app.te index 490ccd02..d24b10e3 100644 --- a/sepolicy/system_app.te +++ b/sepolicy/system_app.te @@ -6,3 +6,6 @@ allow system_app media_rw_data_file:file create_file_perms; # Boot animation allow system_app ctl_bootanim_prop:property_service set; + +# Settings app wants to read ro.adb.secure +get_prop(system_app, adbsecure_prop) diff --git a/sepolicy/system_server.te b/sepolicy/system_server.te index ce9b6bd3..61b85655 100644 --- a/sepolicy/system_server.te +++ b/sepolicy/system_server.te @@ -9,3 +9,5 @@ allow system_server persist_property_file:file { create_file_perms unlink }; allow system_server storage_stub_file:dir { getattr }; allow system_server media_rw_data_file:dir r_dir_perms; + +get_prop(system_server, adbsecure_prop)