#allow system_server sysfs:file { read open getattr }; # for gpu allow system_server abc:dir { read open getattr }; allow system_server serial_device:chr_file rw_file_perms; allow system_server sysfs_extcon:file r_file_perms; # for storage allow system_server storage_stub_file:dir getattr; allow system_server zygote:process getpgid; allow system_server sysfs_net:file r_file_perms; r_dir_file(system_server, metadata_file) #rk_output_hal allow system_server rk_output_hal_service:hwservice_manager find; allow system_server zygote:process { getsched setsched }; allow system_server sysfs_hdmi:file { read open getattr }; add_service(system_server,drm_device_management_service) binder_call(system_server, rk_output_hal) binder_call(system_server, zygote) rw_rockchip_graphic_device(system_server) get_prop(system_server, vendor_base_prop)