aboutsummaryrefslogtreecommitdiffci
path: root/root/tmp/SayaAndy/surface-pro-12-inch-linux-fedora/usr
diff refs
from: back
to: back
| flip
diff options
context:
space:
mode:
Diffstat (limited to 'root/tmp/SayaAndy/surface-pro-12-inch-linux-fedora/usr')
-rw-r--r--root/tmp/SayaAndy/surface-pro-12-inch-linux-fedora/usr/local/share/selinux/iio-qipcrtr.te22
1 files changed, 11 insertions, 11 deletions
diff --git a/root/tmp/SayaAndy/surface-pro-12-inch-linux-fedora/usr/local/share/selinux/iio-qipcrtr.te b/root/tmp/SayaAndy/surface-pro-12-inch-linux-fedora/usr/local/share/selinux/iio-qipcrtr.te
index d92dc21..b3be8fb 100644
--- a/root/tmp/SayaAndy/surface-pro-12-inch-linux-fedora/usr/local/share/selinux/iio-qipcrtr.te
+++ b/root/tmp/SayaAndy/surface-pro-12-inch-linux-fedora/usr/local/share/selinux/iio-qipcrtr.te
@@ -1,16 +1,16 @@
module iio-qipcrtr 1.0;
-// Fedora's policy grants iiosensorproxy_t no qipcrtr_socket permissions at
-// all: the class exists but nothing allows it, because upstream
-// iio-sensor-proxy talks to sensors over IIO and never needed QRTR. The SSC
-// backend libssc brings in here reaches the Qualcomm Sensor Core over the
-// QRTR bus (libssc probes AF_QIPCRTR first; the fastrpc/hexagonrpcd path is
-// what actually serves this board, but the probe alone gets the daemon
-// killed by "QRTR bus unavailable" + "No sensors" without these perms).
-//
-// Hand-written rather than audit2allow'd per-incident: create/bind/... is
-// the full client lifecycle, so a policy reload or libssc update cannot
-// surface a new denied perm one at a time.
+# Fedora's policy grants iiosensorproxy_t no qipcrtr_socket permissions at
+# all: the class exists but nothing allows it, because upstream
+# iio-sensor-proxy talks to sensors over IIO and never needed QRTR. The SSC
+# backend libssc brings in here reaches the Qualcomm Sensor Core over the
+# QRTR bus (libssc probes AF_QIPCRTR first; the fastrpc/hexagonrpcd path is
+# what actually serves this board, but the probe alone gets the daemon
+# killed by "QRTR bus unavailable" + "No sensors" without these perms).
+#
+# Hand-written rather than audit2allow'd per-incident: create/bind/... is
+# the full client lifecycle, so a policy reload or libssc update cannot
+# surface a new denied perm one at a time.
require {
type iiosensorproxy_t;
class qipcrtr_socket { create bind connect read write getattr setattr getopt setopt shutdown };