enforce debugfs constraint on userdebug build am: de2696eb72
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs201-sepolicy/+/17342326 Change-Id: I2008bde5b787053f818a58452f629e5bee8e8ced
This commit is contained in:
2
tracking_denials/hardware_info_app.te
Normal file
2
tracking_denials/hardware_info_app.te
Normal file
@@ -0,0 +1,2 @@
|
||||
# b/208909060
|
||||
dontaudit hardware_info_app vendor_maxfg_debugfs:dir search;
|
||||
@@ -2,4 +2,6 @@
|
||||
dontaudit vendor_init thermal_link_device:file { create };
|
||||
# b/221384939
|
||||
dontaudit vendor_init vendor_battery_defender_prop:property_service { set };
|
||||
# b/226271913
|
||||
dontaudit vendor_init vendor_maxfg_debugfs:file setattr;
|
||||
|
||||
|
||||
@@ -4,7 +4,6 @@ dump_hal(hal_telephony)
|
||||
dump_hal(hal_uwb_vendor)
|
||||
|
||||
userdebug_or_eng(`
|
||||
allow dumpstate vendor_dmabuf_debugfs:file r_file_perms;
|
||||
allow dumpstate media_rw_data_file:file append;
|
||||
')
|
||||
|
||||
|
||||
@@ -22,11 +22,5 @@ allow hardware_info_app sysfs_display:file r_file_perms;
|
||||
allow hardware_info_app sysfs_soc:file r_file_perms;
|
||||
allow hardware_info_app sysfs_chip_id:file r_file_perms;
|
||||
|
||||
# Fuel
|
||||
userdebug_or_eng(`
|
||||
allow hardware_info_app vendor_maxfg_debugfs:dir search;
|
||||
allow hardware_info_app vendor_maxfg_debugfs:file r_file_perms;
|
||||
')
|
||||
|
||||
# Batery history
|
||||
allow hardware_info_app battery_history_device:chr_file r_file_perms;
|
||||
|
||||
Reference in New Issue
Block a user