summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorAmit Pundir <amit.pundir@linaro.org>2018-04-17 00:31:20 +0530
committerAmit Pundir <amit.pundir@linaro.org>2018-04-17 00:31:20 +0530
commit31b9c19457fd4368807ddf32528e5e501ba706e4 (patch)
tree88a0038d8bbc38e69203d26c0f1151da30798e50
parentaa973f2f791a4be05d171e2316888361a79813df (diff)
sepolicy: Set wifi_supplicant policy
Set wifi_supplicant policies to get WiFi working in selinux=enforcing mode. Change-Id: I7667e13c5007197019116dbbe2813f751a4701ce Signed-off-by: Amit Pundir <amit.pundir@linaro.org>
-rw-r--r--sepolicy/hal_wifi_supplicant_default.te10
1 files changed, 10 insertions, 0 deletions
diff --git a/sepolicy/hal_wifi_supplicant_default.te b/sepolicy/hal_wifi_supplicant_default.te
new file mode 100644
index 0000000..3646bac
--- /dev/null
+++ b/sepolicy/hal_wifi_supplicant_default.te
@@ -0,0 +1,10 @@
+# TODO(b/36657258): Remove data_between_core_and_vendor_violators once
+# hal_wifi_supplicant no longer directly accesses wifi_data_file.
+typeattribute hal_wifi_supplicant_default data_between_core_and_vendor_violators;
+
+allow hal_wifi_supplicant_default wifi_data_file:dir create_dir_perms;
+allow hal_wifi_supplicant_default wifi_data_file:file create_file_perms;
+
+# Create a socket for receiving info from wpa
+allow hal_wifi_supplicant_default wpa_socket:dir create_dir_perms;
+allow hal_wifi_supplicant_default wpa_socket:sock_file create_file_perms;