diff --git a/tracking_denials/hal_dumpstate_default.te b/tracking_denials/hal_dumpstate_default.te new file mode 100644 index 00000000..cfc9c4eb --- /dev/null +++ b/tracking_denials/hal_dumpstate_default.te @@ -0,0 +1,2 @@ +# b/188752787 +dontaudit hal_dumpstate_default sysfs_aoc:dir search; diff --git a/tracking_denials/hal_power_default.te b/tracking_denials/hal_power_default.te index ab5c7ecd..260747fc 100644 --- a/tracking_denials/hal_power_default.te +++ b/tracking_denials/hal_power_default.te @@ -10,3 +10,5 @@ dontaudit hal_power_default sysfs:file { read }; dontaudit hal_power_default sysfs:file { getattr }; dontaudit hal_power_default sysfs:file { read }; dontaudit hal_power_default sysfs:file { getattr }; +# b/188752940 +dontaudit hal_power_default hal_power_default:capability dac_read_search;