Merge "SELinux policy: let vold write to device:dir." into jb-mr2-dev
diff --git a/adbd.te b/adbd.te
index c565bd7..8420298 100644
--- a/adbd.te
+++ b/adbd.te
@@ -3,7 +3,7 @@
type adbd, domain, mlstrustedsubject;
allow adbd adb_device:chr_file rw_file_perms;
allow adbd qemu_device:chr_file rw_file_perms;
-allow adbd self:capability { net_raw setgid setuid dac_override sys_boot sys_admin };
+allow adbd self:capability { net_raw setgid setuid setpcap dac_override sys_boot sys_admin };
allow adbd rootfs:file { r_file_perms entrypoint };
allow adbd init:process sigchld;
allow adbd self:tcp_socket *;
diff --git a/policy.version b/policy.version
new file mode 100644
index 0000000..45a4fb7
--- /dev/null
+++ b/policy.version
@@ -0,0 +1 @@
+8
diff --git a/vold.te b/vold.te
index bdd754f..8dd2137 100644
--- a/vold.te
+++ b/vold.te
@@ -57,7 +57,7 @@
allow vold proc:file write;
# Create and mount on /data/tmp_mnt.
-allow vold system_data_file:dir { rw_dir_perms mounton };
+allow vold system_data_file:dir { create rw_dir_perms mounton };
# Set scheduling policy of kernel processes
allow vold kernel:process setsched;