diff --git a/sepolicy/base/system/system_domain.te b/sepolicy/base/system/system_domain.te index b81c623c4a217fde625c3483a89f85cc518ccf80..2183b419c50d132c7d8ed0b0188348c25b14deb7 100644 --- a/sepolicy/base/system/system_domain.te +++ b/sepolicy/base/system/system_domain.te @@ -71,12 +71,12 @@ neverallow { system_domain -bootanimation -media_service -memmgrservice -concurr -vendor_etc_file_violator_file_map } vendor_etc_file:file { map }; neverallow { system_domain -bootanimation -ispserver -media_service -misc -accountmgr -wifi_hal_service -dhardware -dinput -foundation -powermgr -hdf_devmgr -hiview -memmgrservice -audio_server -sensors -av_codec_service -multimodalinput -charger -concurrent_task_service - -resource_schedule_service -appspawn -cjappspawn -init -telephony_sa -vendor_etc_file_violator_file_open developer_only(`-hnp') -hnp_violator -rgm_violator_ohos_vendor_etc_file_open -teecd } vendor_etc_file:file { open }; + -resource_schedule_service -appspawn -cjappspawn -init -telephony_sa -vendor_etc_file_violator_file_open developer_only(`-hnp') -hnp_violator -rgm_violator_ohos_vendor_etc_file_open -teecd -resource_schedule_executor } vendor_etc_file:file { open }; neverallow { system_domain -bootanimation -ispserver -media_service -misc -accountmgr -wifi_hal_service -dhardware -dinput -msdp_sa -foundation -powermgr -hdf_devmgr -hiview -memmgrservice -audio_server -sensors -av_codec_service -multimodalinput -charger -concurrent_task_service - -resource_schedule_service -appspawn -cjappspawn -init -telephony_sa -vendor_etc_file_violator_file_read developer_only(`-hnp') -hnp_violator -rgm_violator_ohos_vendor_etc_file_read -teecd } vendor_etc_file:file { read }; + -resource_schedule_service -appspawn -cjappspawn -init -telephony_sa -vendor_etc_file_violator_file_read developer_only(`-hnp') -hnp_violator -rgm_violator_ohos_vendor_etc_file_read -teecd -resource_schedule_executor } vendor_etc_file:file { read }; neverallow { system_domain -bootanimation -ispserver -media_service -misc -accountmgr -wifi_hal_service -dhardware -dinput -foundation -powermgr -hdf_devmgr -memmgrservice -audio_server -sensors -av_codec_service -multimodalinput -charger -concurrent_task_service - -resource_schedule_service -appspawn -cjappspawn -init -vendor_etc_file_violator_file_getattr developer_only(`-hnp') -hnp_violator -rgm_violator_ohos_vendor_etc_file_getattr -teecd } vendor_etc_file:file { getattr }; + -resource_schedule_service -appspawn -cjappspawn -init -vendor_etc_file_violator_file_getattr developer_only(`-hnp') -hnp_violator -rgm_violator_ohos_vendor_etc_file_getattr -teecd -resource_schedule_executor } vendor_etc_file:file { getattr }; neverallow { system_domain -vendor_etc_file_violator_file_relabelto } vendor_etc_file:file { relabelto }; neverallow { system_domain } vendor_etc_file:{ blk_file chr_file fifo_file lnk_file sock_file } *; diff --git a/sepolicy/ohos_policy/resourceschedule/resource_schedule_service/system/resource_schedule_executor.te b/sepolicy/ohos_policy/resourceschedule/resource_schedule_service/system/resource_schedule_executor.te index b61476b9d4e625649fe6b084de761955090e86e9..40736d6f3623e9a036906b463ee74016d8fbafba 100644 --- a/sepolicy/ohos_policy/resourceschedule/resource_schedule_service/system/resource_schedule_executor.te +++ b/sepolicy/ohos_policy/resourceschedule/resource_schedule_service/system/resource_schedule_executor.te @@ -46,6 +46,7 @@ allowxperm resource_schedule_executor sys_file:file ioctl { 0x5413 }; allow resource_schedule_executor sys_prod_ressched_file:dir { search }; allow resource_schedule_executor sys_prod_ressched_file:file { getattr open read }; allow resource_schedule_executor vendor_etc_file:dir { search }; +allow resource_schedule_executor vendor_etc_file:file { getattr read open }; allow resource_schedule_executor vendor_etc_ressched_file:dir { search }; allow resource_schedule_executor vendor_etc_ressched_file:file { open read }; allow resource_schedule_executor normal_hap_attr:process { sigkill };