Merge "Disallow sysfs_leds to coredomains." am: 5d5284ad93 am: abe248d14d
am: 977949e360
Change-Id: I9b145b354413e77e02b67e83f411cec709c7d8e1
diff --git a/private/coredomain.te b/private/coredomain.te
index 244c83c..c8f2b1d 100644
--- a/private/coredomain.te
+++ b/private/coredomain.te
@@ -1,2 +1,17 @@
get_prop(coredomain, pm_prop)
get_prop(coredomain, exported_pm_prop)
+
+full_treble_only(`
+neverallow {
+ coredomain
+ -init
+ -vendor_init
+
+ # generic access to sysfs_type
+ -ueventd
+ -vold
+ -priv_app
+ -storaged
+ -system_app
+} sysfs_leds:file *;
+')