Merge "init: tighten sysfs_type permissions"
diff --git a/public/init.te b/public/init.te
index 3a2d667..450afd8 100644
--- a/public/init.te
+++ b/public/init.te
@@ -214,7 +214,7 @@
-contextmount_type
-proc
-sdcard_type
- -sysfs
+ -sysfs_type
-rootfs
}:file { open read setattr };
allow init { fs_type -contextmount_type -sdcard_type -rootfs }:dir { open read setattr search };
@@ -304,6 +304,10 @@
sysfs_zram
}:file w_file_perms;
+allow init {
+ sysfs_dt_firmware_android
+}:file r_file_perms;
+
# init chmod/chown access to /sys files.
allow init {
sysfs_android_usb
@@ -312,6 +316,8 @@
sysfs_leds
sysfs_lowmemorykiller
sysfs_power
+ sysfs_vibrator
+ sysfs_wake_lock
}:file setattr;
# Set usermodehelpers.