device_google_gs-common/aoc/sepolicy
Bruce Po e15af041dd Fix aocx selinux dumpstate permissions
After switching aocxd to stable AIDL, we encountered some permissions
issues associated with dumpstate:

dumpstate: type=1400 audit(0.0:548): avc:  denied  { call } for  scontext=u:r:dumpstate:s0 tcontext=u:r:aocxd:s0 tclass=binder permissive=0

dumpstate: type=1400 audit(0.0:17): avc:  denied  { use } for  path="pipe:[214567]" dev="pipefs" ino=214567 scontext=u:r:aocxd:s0 tcontext=u:r:dumpstate:s0 tclass=fd permissive=0

dumpstate: type=1400 audit(0.0:15): avc:  denied  { write } for  path="pipe:[212933]" dev="pipefs" ino=212933 scontext=u:r:aocxd:s0 tcontext=u:r:dumpstate:s0 tclass=fifo_file permissive=0

TEST:
make selinux_policy -j128
adb push $ANDROID_PRODUCT_OUT/vendor/etc/selinux/* /vendor/etc/selinux
adb reboot
adb root
adb bugreport

BUG: 347156752
Change-Id: I188263ee9b186736a48fd3a0cfa83745e2e54108
2024-06-14 15:36:14 -07:00
..
aocd.te aoc: add policy to read system property 2023-12-13 19:32:43 +00:00
aocdump.te move aoc settings to gs-common 2022-10-20 11:23:26 +08:00
aocxd.te Fix aocx selinux dumpstate permissions 2024-06-14 15:36:14 -07:00
device.te audio: add audio hal aidl service 2023-03-09 13:47:57 +08:00
dump_aoc.te gs-common:aoc: correct aoc information in the bugreport 2023-04-26 10:51:44 +00:00
dumpstate.te Fix aocx selinux dumpstate permissions 2024-06-14 15:36:14 -07:00
file.te aoc: add permissions for new sysfs node 2023-11-17 16:17:29 +00:00
file_contexts Add the new IPC and ring buffer files. 2024-05-31 02:04:54 +00:00
property.te aoc: add policy to read system property 2023-12-13 19:32:43 +00:00
property_contexts aoc: add policy to read system property 2023-12-13 19:32:43 +00:00
service.te selinux move aocx from vndservice to service 2024-05-31 12:42:10 -07:00
service_contexts selinux move aocx from vndservice to service 2024-05-31 12:42:10 -07:00