Merge "Disallow sysfs_leds to coredomains." am: 5d5284ad93
am: abe248d14d
Change-Id: Id7202a1c4a991e0f130bf34a0adb7f913434a617
diff --git a/private/coredomain.te b/private/coredomain.te
index 244c83c..c8f2b1d 100644
--- a/private/coredomain.te
+++ b/private/coredomain.te
@@ -1,2 +1,17 @@
get_prop(coredomain, pm_prop)
get_prop(coredomain, exported_pm_prop)
+
+full_treble_only(`
+neverallow {
+ coredomain
+ -init
+ -vendor_init
+
+ # generic access to sysfs_type
+ -ueventd
+ -vold
+ -priv_app
+ -storaged
+ -system_app
+} sysfs_leds:file *;
+')