diff --git a/tracking_denials/hal_graphics_composer_default.te b/tracking_denials/hal_graphics_composer_default.te index 87535c37..71e93ce4 100644 --- a/tracking_denials/hal_graphics_composer_default.te +++ b/tracking_denials/hal_graphics_composer_default.te @@ -31,3 +31,7 @@ dontaudit hal_graphics_composer_default sysfs_display:file { write }; # b/208721526 dontaudit hal_graphics_composer_default dumpstate:fd { use }; dontaudit hal_graphics_composer_default dumpstate:fifo_file { write }; +# b/209705194 +dontaudit hal_graphics_composer_default sysfs_sensors:file { getattr }; +dontaudit hal_graphics_composer_default sysfs_sensors:file { open }; +dontaudit hal_graphics_composer_default sysfs_sensors:file { write }; diff --git a/tracking_denials/hal_power_stats_default.te b/tracking_denials/hal_power_stats_default.te index ff6abb06..bd54b733 100644 --- a/tracking_denials/hal_power_stats_default.te +++ b/tracking_denials/hal_power_stats_default.te @@ -25,3 +25,6 @@ dontaudit hal_power_stats_default sysfs_wifi:dir { search }; dontaudit hal_power_stats_default sysfs_wifi:file { getattr }; dontaudit hal_power_stats_default sysfs_wifi:file { open }; dontaudit hal_power_stats_default sysfs_wifi:file { read }; +# b/209704948 +dontaudit hal_power_stats_default sysfs_sensors:file { open }; +dontaudit hal_power_stats_default sysfs_sensors:file { read }; diff --git a/tracking_denials/priv_app.te b/tracking_denials/priv_app.te index 6e133e5b..f57731e9 100644 --- a/tracking_denials/priv_app.te +++ b/tracking_denials/priv_app.te @@ -7,3 +7,9 @@ dontaudit priv_app vendor_apex_file:dir { search }; dontaudit priv_app vendor_apex_file:file { getattr }; dontaudit priv_app vendor_apex_file:file { open }; dontaudit priv_app vendor_apex_file:file { read }; +# b/209703854 +dontaudit priv_app vendor_file:file { execute }; +dontaudit priv_app vendor_file:file { getattr }; +dontaudit priv_app vendor_file:file { map }; +dontaudit priv_app vendor_file:file { open }; +dontaudit priv_app vendor_file:file { read }; diff --git a/tracking_denials/rlsservice.te b/tracking_denials/rlsservice.te index 604af460..e0a6630a 100644 --- a/tracking_denials/rlsservice.te +++ b/tracking_denials/rlsservice.te @@ -22,3 +22,6 @@ dontaudit rlsservice device:dir { read }; dontaudit rlsservice device:dir { watch }; dontaudit rlsservice sysfs:file { open }; dontaudit rlsservice sysfs:file { read }; +# b/209705394 +dontaudit rlsservice sysfs_sensors:file { open }; +dontaudit rlsservice sysfs_sensors:file { read }; diff --git a/tracking_denials/system_suspend.te b/tracking_denials/system_suspend.te new file mode 100644 index 00000000..d8120564 --- /dev/null +++ b/tracking_denials/system_suspend.te @@ -0,0 +1,6 @@ +# b/209705335 +dontaudit system_suspend_server sysfs:dir { open }; +dontaudit system_suspend_server sysfs:dir { read }; +dontaudit system_suspend_server sysfs:file { getattr }; +dontaudit system_suspend_server sysfs:file { open }; +dontaudit system_suspend_server sysfs:file { read };