diff --git a/tracking_denials/crash_dump.te b/tracking_denials/crash_dump.te new file mode 100644 index 00000000..b736b20d --- /dev/null +++ b/tracking_denials/crash_dump.te @@ -0,0 +1,7 @@ +# b/207300335 +dontaudit crash_dump hwservicemanager_prop:file { getattr }; +dontaudit crash_dump hwservicemanager_prop:file { map }; +dontaudit crash_dump hwservicemanager_prop:file { open }; +dontaudit crash_dump qemu_sf_lcd_density_prop:file { getattr }; +dontaudit crash_dump qemu_sf_lcd_density_prop:file { map }; +dontaudit crash_dump qemu_sf_lcd_density_prop:file { open }; diff --git a/tracking_denials/hal_camera_default.te b/tracking_denials/hal_camera_default.te index 70436e89..44f87210 100644 --- a/tracking_denials/hal_camera_default.te +++ b/tracking_denials/hal_camera_default.te @@ -52,3 +52,5 @@ dontaudit hal_camera_default system_server:binder { call }; dontaudit hal_camera_default device:chr_file { ioctl }; dontaudit hal_camera_default device:chr_file { open }; dontaudit hal_camera_default device:chr_file { read }; +# b/207300298 +dontaudit hal_camera_default vendor_camera_data_file:file { getattr }; diff --git a/tracking_denials/priv_app.te b/tracking_denials/priv_app.te index c966f4e6..871e43f1 100644 --- a/tracking_denials/priv_app.te +++ b/tracking_denials/priv_app.te @@ -2,3 +2,9 @@ dontaudit priv_app vendor_default_prop:file { getattr }; dontaudit priv_app vendor_default_prop:file { map }; dontaudit priv_app vendor_default_prop:file { open }; +# b/207300281 +dontaudit priv_app vendor_file:file { execute }; +dontaudit priv_app vendor_file:file { getattr }; +dontaudit priv_app vendor_file:file { map }; +dontaudit priv_app vendor_file:file { open }; +dontaudit priv_app vendor_file:file { read }; diff --git a/tracking_denials/radio.te b/tracking_denials/radio.te new file mode 100644 index 00000000..a71d5772 --- /dev/null +++ b/tracking_denials/radio.te @@ -0,0 +1,2 @@ +# b/207300315 +dontaudit radio sysfs_vendor_sched:dir { search }; diff --git a/tracking_denials/uwb_vendor_app.te b/tracking_denials/uwb_vendor_app.te new file mode 100644 index 00000000..57127193 --- /dev/null +++ b/tracking_denials/uwb_vendor_app.te @@ -0,0 +1,5 @@ +# b/207300261 +dontaudit uwb_vendor_app vendor_secure_element_prop:file { getattr }; +dontaudit uwb_vendor_app vendor_secure_element_prop:file { map }; +dontaudit uwb_vendor_app vendor_secure_element_prop:file { open }; +dontaudit uwb_vendor_app vendor_secure_element_prop:file { read };