diff --git a/tracking_denials/hardware_info_app.te b/tracking_denials/hardware_info_app.te index 810cb701..8e02952f 100644 --- a/tracking_denials/hardware_info_app.te +++ b/tracking_denials/hardware_info_app.te @@ -1,12 +1,8 @@ # b/181177926 -dontaudit hardware_info_app sysfs_scsi_devices_0000:file { getattr }; -dontaudit hardware_info_app sysfs_scsi_devices_0000:file { open }; dontaudit hardware_info_app sysfs_batteryinfo:file { read }; dontaudit hardware_info_app sysfs:file { read }; dontaudit hardware_info_app sysfs:file { open }; dontaudit hardware_info_app sysfs:file { getattr }; -dontaudit hardware_info_app sysfs_scsi_devices_0000:dir { search }; -dontaudit hardware_info_app sysfs_scsi_devices_0000:file { read }; dontaudit hardware_info_app sysfs_batteryinfo:dir { search }; # b/181914888 dontaudit hardware_info_app sysfs_batteryinfo:file { open }; diff --git a/whitechapel/vendor/google/hardware_info_app.te b/whitechapel/vendor/google/hardware_info_app.te index b94d1138..90ed9a60 100644 --- a/whitechapel/vendor/google/hardware_info_app.te +++ b/whitechapel/vendor/google/hardware_info_app.te @@ -11,3 +11,7 @@ allow hardware_info_app sysfs_display:file r_file_perms; # Audio allow hardware_info_app sysfs_pixelstats:dir search; allow hardware_info_app sysfs_pixelstats:file r_file_perms; + +# Storage +allow hardware_info_app sysfs_scsi_devices_0000:dir search; +allow hardware_info_app sysfs_scsi_devices_0000:file r_file_perms; \ No newline at end of file