diff --git a/sepolicy/ohos_policy/distributeddatamgr/sqlite3/system/sqlite3.te b/sepolicy/ohos_policy/distributeddatamgr/sqlite3/system/sqlite3.te index 69315bf1bd241b69347a54355dbe83013578c141..f511a51395bebc25eea820a4ed7c546908aacddc 100644 --- a/sepolicy/ohos_policy/distributeddatamgr/sqlite3/system/sqlite3.te +++ b/sepolicy/ohos_policy/distributeddatamgr/sqlite3/system/sqlite3.te @@ -94,6 +94,9 @@ allow sqlite3 tty_device:chr_file { ioctl read write }; # avc: denied { ioctl } for pid=25124, comm="/bin/sqlite3" name="0" dev="0" major=136 minor=0 ioctlcmd=0x5413 scontext=u:r:sqlite3:s0 tcontext=u:object_r:tty_device:s0 tclass=chr_file permissive=1 allowxperm sqlite3 tty_device:chr_file ioctl { 0x5413 }; + +# avc: denied { get } for service=182 sid=u:r:sqlite3:s0 scontext=u:r:sqlite3:s0 tcontext=u:object_r:sa_dataobs_mgr_service_service:s0 tclass=samgr_class permissive=1 +allow sqlite3 sa_dataobs_mgr_service_service:samgr_class { get }; ') # only shell allowed execute sqlite3_exec