sepolicy: add more drm devices

* Pi 5 has independent cards for DSI-0, DSI-1, DPI, and VEC.
  In theory we could have two DSI displays so add two more entries.

avc:  denied  { ioctl } for  path="/dev/dri/card2" dev="tmpfs" ino=749 ioctlcmd=0x64bc scontext=u:r:hal_graphics_composer_default:s0 tcontext=u:object_r:device:s0 tclass=chr_file permissive=1
This commit is contained in:
Konsta
2025-03-19 19:29:01 +02:00
parent c7eeef4b58
commit 61e83a2939

View File

@@ -16,6 +16,8 @@
/dev/dri u:object_r:gpu_device:s0 /dev/dri u:object_r:gpu_device:s0
/dev/dri/card0 u:object_r:gpu_device:s0 /dev/dri/card0 u:object_r:gpu_device:s0
/dev/dri/card1 u:object_r:gpu_device:s0 /dev/dri/card1 u:object_r:gpu_device:s0
/dev/dri/card2 u:object_r:gpu_device:s0
/dev/dri/card3 u:object_r:gpu_device:s0
/dev/dri/renderD128 u:object_r:gpu_device:s0 /dev/dri/renderD128 u:object_r:gpu_device:s0
/vendor/bin/hw/android\.hardware\.graphics\.allocator-service\.minigbm_gbm_mesa u:object_r:hal_graphics_allocator_default_exec:s0 /vendor/bin/hw/android\.hardware\.graphics\.allocator-service\.minigbm_gbm_mesa u:object_r:hal_graphics_allocator_default_exec:s0
/vendor/lib(64)?/hw/mapper\.minigbm_gbm_mesa\.so u:object_r:same_process_hal_file:s0 /vendor/lib(64)?/hw/mapper\.minigbm_gbm_mesa\.so u:object_r:same_process_hal_file:s0