Merge "Allow system_server access to aconfigd_mainline socket as well" into main am: 79009bc283
Original change: https://android-review.googlesource.com/c/platform/system/sepolicy/+/3394096
Change-Id: Idf37ea33ce56406ee8e9cf1c014c9cebdc3d84d6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
diff --git a/private/system_server.te b/private/system_server.te
index 9528071..01097f2 100644
--- a/private/system_server.te
+++ b/private/system_server.te
@@ -1533,8 +1533,11 @@
allow system_server watchdog_metadata_file:dir rw_dir_perms;
allow system_server watchdog_metadata_file:file create_file_perms;
-allow system_server aconfigd_socket:sock_file {read write};
-allow system_server aconfigd:unix_stream_socket connectto;
+# allow system_server write to aconfigd socket
+unix_socket_connect(system_server, aconfigd, aconfigd);
+
+# allow system_server write to aconfigd_mainline socket
+unix_socket_connect(system_server, aconfigd_mainline, aconfigd_mainline);
allow system_server repair_mode_metadata_file:dir rw_dir_perms;
allow system_server repair_mode_metadata_file:file create_file_perms;