summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorAndroid Build Coastguard Worker <android-build-coastguard-worker@google.com>2023-07-07 00:56:06 +0000
committerAndroid Build Coastguard Worker <android-build-coastguard-worker@google.com>2023-07-07 00:56:06 +0000
commit127c044604b83094fba5405c0a34e3f1b8653f11 (patch)
tree43e58fc5e631e2db62e39af64f5457138e773059
parent9a49c9bfb889bb03070c1f1eafcd39877294e777 (diff)
parent56723e77fcd64d84e9dc5478932f3533efdd54a0 (diff)
downloadbarbet-sepolicy-aml_wif_341610000.tar.gz
Change-Id: I3d56cde9f2345e1acb5a958b7997d5eb9b551ad3
-rw-r--r--tracking_denials/bug_map4
-rw-r--r--tracking_denials/dumpstate.te2
-rw-r--r--tracking_denials/hal_dumpstate_impl.te2
-rw-r--r--tracking_denials/incidentd.te2
-rw-r--r--tracking_denials/mediacodec.te4
-rw-r--r--tracking_denials/mediaserver.te4
-rw-r--r--tracking_denials/pixelstats_vendor.te2
-rw-r--r--tracking_denials/platform_app.te2
-rw-r--r--vendor/google/pixelstats_vendor.te6
9 files changed, 11 insertions, 17 deletions
diff --git a/tracking_denials/bug_map b/tracking_denials/bug_map
new file mode 100644
index 0000000..11c183f
--- /dev/null
+++ b/tracking_denials/bug_map
@@ -0,0 +1,4 @@
+dumpstate incident process b/238571134
+dumpstate system_data_file dir b/264600045
+hal_drm_widevine default_prop file b/238263941
+system_server vendor_incremental_module file b/264483452
diff --git a/tracking_denials/dumpstate.te b/tracking_denials/dumpstate.te
new file mode 100644
index 0000000..21e2bf1
--- /dev/null
+++ b/tracking_denials/dumpstate.te
@@ -0,0 +1,2 @@
+# b/277155697
+dontaudit dumpstate default_android_service:service_manager { find };
diff --git a/tracking_denials/hal_dumpstate_impl.te b/tracking_denials/hal_dumpstate_impl.te
deleted file mode 100644
index 8fa3265..0000000
--- a/tracking_denials/hal_dumpstate_impl.te
+++ /dev/null
@@ -1,2 +0,0 @@
-# b/193476528
-dontaudit hal_dumpstate_impl sysfs:file getattr;
diff --git a/tracking_denials/incidentd.te b/tracking_denials/incidentd.te
deleted file mode 100644
index 87a9e93..0000000
--- a/tracking_denials/incidentd.te
+++ /dev/null
@@ -1,2 +0,0 @@
-# b/187011252
-dontaudit incidentd apex_info_file:file getattr;
diff --git a/tracking_denials/mediacodec.te b/tracking_denials/mediacodec.te
deleted file mode 100644
index ea4b461..0000000
--- a/tracking_denials/mediacodec.te
+++ /dev/null
@@ -1,4 +0,0 @@
-# b/170356952
-dontaudit mediacodec sysfs_msm_subsys:file read ;
-dontaudit mediacodec sysfs_msm_subsys:file open ;
-dontaudit mediacodec sysfs_msm_subsys:file getattr ;
diff --git a/tracking_denials/mediaserver.te b/tracking_denials/mediaserver.te
deleted file mode 100644
index 619c271..0000000
--- a/tracking_denials/mediaserver.te
+++ /dev/null
@@ -1,4 +0,0 @@
-# b/170356968
-dontaudit mediaserver sysfs_msm_subsys:file read ;
-dontaudit mediaserver sysfs_msm_subsys:file open ;
-dontaudit mediaserver sysfs_msm_subsys:file getattr ;
diff --git a/tracking_denials/pixelstats_vendor.te b/tracking_denials/pixelstats_vendor.te
deleted file mode 100644
index 0f6e3a3..0000000
--- a/tracking_denials/pixelstats_vendor.te
+++ /dev/null
@@ -1,2 +0,0 @@
-# b/182338901
-dontaudit pixelstats_vendor servicemanager:binder call;
diff --git a/tracking_denials/platform_app.te b/tracking_denials/platform_app.te
new file mode 100644
index 0000000..0988014
--- /dev/null
+++ b/tracking_denials/platform_app.te
@@ -0,0 +1,2 @@
+# b/265359406
+dontaudit platform_app hal_wireless_charger_service:service_manager { find };
diff --git a/vendor/google/pixelstats_vendor.te b/vendor/google/pixelstats_vendor.te
index c45b997..ffd2388 100644
--- a/vendor/google/pixelstats_vendor.te
+++ b/vendor/google/pixelstats_vendor.te
@@ -14,11 +14,11 @@ r_dir_file(pixelstats_vendor, sysfs_batteryinfo)
# UeventListener
allow pixelstats_vendor self:netlink_kobject_uevent_socket create_socket_perms_no_ioctl;
-# wlc
-allow pixelstats_vendor sysfs_wlc:dir search;
-
# OrientationCollector
+# HIDL sensorservice
allow pixelstats_vendor fwk_sensor_hwservice:hwservice_manager find;
+# AIDL sensorservice
+allow pixelstats_vendor fwk_sensor_service:service_manager find;
binder_call(pixelstats_vendor, system_server)
binder_use(pixelstats_vendor)
allow pixelstats_vendor fwk_stats_service:service_manager find;