Files
android_device_brcm_rpi5/sepolicy/file_contexts
Konsta 67433cbc2b sepolicy: graphics: address some denials
* Labeling vendor allocator libraries became necessary for some reason
  after moving minigbm gralloc to APEX.
* Address remaining drm_hwcomposer denials.
2025-11-10 17:17:55 +02:00

28 lines
1.3 KiB
Plaintext

# CEC
/dev/cec0 u:object_r:cec_device:s0
/dev/cec1 u:object_r:cec_device:s0
# DRM
/data/vendor/mediadrm(/.*)? u:object_r:mediadrm_vendor_data_file:s0
# Graphics
/dev/dri(/.*)? u:object_r:gpu_device:s0
/vendor/lib64/android\.hardware\.graphics\.allocator@[2-4]\.0\.so u:object_r:same_process_hal_file:s0
/vendor/lib64/libdrm\.so u:object_r:same_process_hal_file:s0
/vendor/lib64/libgallium_dri\.so u:object_r:same_process_hal_file:s0
/vendor/lib64/libui\.so u:object_r:same_process_hal_file:s0
# Partitions
/dev/block/mmcblk0p1 u:object_r:boot_block_device:s0
/dev/block/mmcblk0p2 u:object_r:system_block_device:s0
/dev/block/mmcblk0p3 u:object_r:system_block_device:s0
/dev/block/mmcblk0p4 u:object_r:userdata_block_device:s0
/dev/block/nvme0n1p1 u:object_r:boot_block_device:s0
/dev/block/nvme0n1p2 u:object_r:system_block_device:s0
/dev/block/nvme0n1p3 u:object_r:system_block_device:s0
/dev/block/nvme0n1p4 u:object_r:userdata_block_device:s0
/dev/block/sda1 u:object_r:boot_block_device:s0
/dev/block/sda2 u:object_r:system_block_device:s0
/dev/block/sda3 u:object_r:system_block_device:s0
/dev/block/sda4 u:object_r:userdata_block_device:s0