Add sepolicy for ACPI bert_collector
bert_collector is a deamon that runs at boot, collects ACPI BERT
reports and sends them to DropBox.
Adds bert_collector.te policy for bert_collector deamon permissions.
Adds sysfs_firmware_acpi_tables context for /sys/firmware/acpi/tables.
Adds property acpi.bert_collector.start for starting bert_collector.
Bug: 357626966
Test: m && atest bert_collector_test
Change-Id: I4c583f3a9121474235ea8c78f65b74df86936a0b
diff --git a/private/file.te b/private/file.te
index 70b8523..662d5cc 100644
--- a/private/file.te
+++ b/private/file.te
@@ -182,6 +182,9 @@
# Type for /sys/kernel/mm/pgsize_migration/enabled
type sysfs_pgsize_migration, fs_type, sysfs_type;
+# /sys/firmware/acpi/tables
+type sysfs_firmware_acpi_tables, fs_type, sysfs_type;
+
# Allow files to be created in their appropriate filesystems.
allow fs_type self:filesystem associate;
allow cgroup tmpfs:filesystem associate;