diff --git a/tracking_denials/hal_sensors_default.te b/tracking_denials/hal_sensors_default.te deleted file mode 100644 index b3331836..00000000 --- a/tracking_denials/hal_sensors_default.te +++ /dev/null @@ -1,59 +0,0 @@ -# b/182086633 -dontaudit hal_sensors_default servicemanager:binder { call }; -dontaudit hal_sensors_default device:dir { read }; -dontaudit hal_sensors_default device:dir { watch }; -dontaudit hal_sensors_default aoc_device:chr_file { read write }; -dontaudit hal_sensors_default aoc_device:chr_file { open }; -dontaudit hal_sensors_default mnt_vendor_file:dir { search }; -dontaudit hal_sensors_default persist_file:dir { search }; -dontaudit hal_sensors_default persist_file:dir { getattr }; -dontaudit hal_sensors_default persist_file:dir { read }; -dontaudit hal_sensors_default persist_file:dir { open }; -dontaudit hal_sensors_default persist_file:file { getattr }; -dontaudit hal_sensors_default persist_file:file { read }; -dontaudit hal_sensors_default persist_file:file { open }; -dontaudit hal_sensors_default vendor_data_file:dir { read }; -dontaudit hal_sensors_default vendor_data_file:dir { open }; -dontaudit hal_sensors_default vendor_data_file:file { getattr }; -dontaudit hal_sensors_default vendor_data_file:file { read }; -dontaudit hal_sensors_default vendor_data_file:file { open }; -dontaudit hal_sensors_default fwk_stats_service:service_manager { find }; -dontaudit hal_sensors_default servicemanager:binder { call }; -dontaudit hal_sensors_default servicemanager:binder { transfer }; -dontaudit hal_sensors_default servicemanager:binder { transfer }; -dontaudit hal_sensors_default servicemanager:binder { call }; -dontaudit hal_sensors_default aoc_device:chr_file { getattr }; -dontaudit hal_sensors_default aoc_device:chr_file { read write }; -dontaudit hal_sensors_default aoc_device:chr_file { open }; -dontaudit hal_sensors_default vendor_data_file:file { write }; -dontaudit hal_sensors_default sysfs_aoc_boottime:file { read }; -dontaudit hal_sensors_default sysfs_aoc_boottime:file { open }; -dontaudit hal_sensors_default sysfs_aoc_boottime:file { getattr }; -dontaudit hal_sensors_default vendor_data_file:file { write }; -dontaudit hal_sensors_default vendor_data_file:file { read }; -dontaudit hal_sensors_default vendor_data_file:file { getattr }; -dontaudit hal_sensors_default persist_file:dir { search }; -dontaudit hal_sensors_default vendor_data_file:dir { open }; -dontaudit hal_sensors_default aoc_device:chr_file { read write }; -dontaudit hal_sensors_default vendor_data_file:dir { read }; -dontaudit hal_sensors_default persist_file:file { open }; -dontaudit hal_sensors_default vendor_data_file:file { open }; -dontaudit hal_sensors_default sysfs_aoc_boottime:file { getattr }; -dontaudit hal_sensors_default sysfs_aoc_boottime:file { open }; -dontaudit hal_sensors_default sysfs_aoc_boottime:file { read }; -dontaudit hal_sensors_default persist_file:file { read }; -dontaudit hal_sensors_default persist_file:file { getattr }; -dontaudit hal_sensors_default device:dir { read }; -dontaudit hal_sensors_default persist_file:dir { open }; -dontaudit hal_sensors_default persist_file:dir { read }; -dontaudit hal_sensors_default persist_file:dir { getattr }; -dontaudit hal_sensors_default vendor_data_file:file { open }; -dontaudit hal_sensors_default mnt_vendor_file:dir { search }; -dontaudit hal_sensors_default device:dir { read }; -dontaudit hal_sensors_default device:dir { watch }; -dontaudit hal_sensors_default servicemanager:binder { transfer }; -dontaudit hal_sensors_default aoc_device:chr_file { open }; -# b/182523946 -dontaudit hal_sensors_default chre_socket:sock_file { write }; -dontaudit hal_sensors_default chre:unix_stream_socket { connectto }; -dontaudit hal_sensors_default chre:unix_stream_socket { connectto }; diff --git a/usf/sensor_hal.te b/usf/sensor_hal.te index afb74634..84d1caff 100644 --- a/usf/sensor_hal.te +++ b/usf/sensor_hal.te @@ -20,3 +20,34 @@ allow hal_sensors_default sysfs_aoc_boottime:file rw_file_perms; # Allow create thread to watch AOC's device. allow hal_sensors_default device:dir r_dir_perms; + +# Allow access to the files of CDT information. +r_dir_file(hal_sensors_default, sysfs_chosen) + +# Allow display_info_service access to the backlight driver. +allow hal_sensors_default sysfs_leds:dir search; +allow hal_sensors_default sysfs_leds:file rw_file_perms; + +# Allow access to the power supply files for MagCC. +r_dir_file(hal_sensors_default, sysfs_batteryinfo) +allow hal_sensors_default sysfs_wlc:dir r_dir_perms; + +# Allow access to sensor service for sensor_listener. +binder_call(hal_sensors_default, system_server); + +# Allow access to the stats service. +allow hal_sensors_default fwk_stats_hwservice:hwservice_manager find; + +# Allow access to the sysfs_aoc. +allow hal_sensors_default sysfs_aoc:dir search; + +# +# Suez type enforcements. +# + +# Allow SensorSuez to connect AIDL stats. +binder_use(hal_sensors_default); +allow hal_sensors_default fwk_stats_service:service_manager find; + +# Allow access to CHRE socket to connect to nanoapps. +unix_socket_connect(hal_sensors_default, chre, chre) diff --git a/whitechapel/vendor/google/hal_sensors_default.te b/whitechapel/vendor/google/hal_sensors_default.te deleted file mode 100644 index 396fd3c5..00000000 --- a/whitechapel/vendor/google/hal_sensors_default.te +++ /dev/null @@ -1,23 +0,0 @@ -# Allow access to the files of CDT information. -r_dir_file(hal_sensors_default, sysfs_chosen) - -# Allow access to the leds driver. -allow hal_sensors_default sysfs_leds:dir search; -allow hal_sensors_default sysfs_leds:file rw_file_perms; - -# Allow access to the power supply files for MagCC. -r_dir_file(hal_sensors_default, sysfs_batteryinfo) -allow hal_sensors_default sysfs_wlc:dir r_dir_perms; - -# Allow access to sensor service for sensor_listener. -binder_call(hal_sensors_default, system_server); - -# Allow access to the stats service. -allow hal_sensors_default fwk_stats_hwservice:hwservice_manager find; - -# Allow access to the sysfs_aoc. -allow hal_sensors_default sysfs_aoc:dir search; - -# Allow SensorSuez to connect AIDL stats. -binder_use(hal_sensors_default); -allow hal_sensors_default fwk_stats_service:service_manager find;