dispatch service related error

Bug: 202906787
Test: pts-tradefed run pts -m PtsSELinuxTest

Change-Id: Ifbdf1de156994572b8fedfd18180d3821ef1594c
This commit is contained in:
Adam Shih 2021-10-14 10:48:50 +08:00
parent bf900e2ae5
commit bfd5097be2
28 changed files with 82 additions and 1 deletions

View file

@ -14,7 +14,6 @@ dontaudit domain fs_type:filesystem *;
dontaudit domain dev_type:file *;
dontaudit domain dev_type:chr_file *;
dontaudit domain dev_type:blk_file *;
dontaudit domain service_manager_type:service_manager *;
dontaudit domain domain:capability *;
dontaudit domain domain:binder *;
dontaudit domain domain:socket_class_set *;

2
tracking_denials/cbd.te Normal file
View file

@ -0,0 +1,2 @@
# b/202906831
dontaudit cbd unlabeled:lnk_file { read };

View file

@ -0,0 +1,3 @@
# b/202906931
dontaudit citadeld default_android_vndservice:service_manager { add };
dontaudit citadeld hal_power_stats_vendor_service:service_manager { find };

View file

@ -0,0 +1,3 @@
# b/202906784
dontaudit hal_camera_default edgetpu_vendor_server:fd { use };
dontaudit hal_camera_default hal_radioext_hwservice:hwservice_manager { find };

View file

@ -0,0 +1,4 @@
# b/202906980
dontaudit hal_drm_widevine hal_drm_hwservice:hwservice_manager { add };
dontaudit hal_drm_widevine hal_drm_hwservice:hwservice_manager { find };
dontaudit hal_drm_widevine hidl_base_hwservice:hwservice_manager { add };

View file

@ -0,0 +1,4 @@
# b/202906981
dontaudit hal_fingerprint_default block_device:dir { search };
dontaudit hal_fingerprint_default hal_fingerprint_ext_hwservice:hwservice_manager { add };
dontaudit hal_fingerprint_default hal_fingerprint_ext_hwservice:hwservice_manager { find };

View file

@ -0,0 +1,5 @@
# b/202906947
dontaudit hal_graphics_composer_default vendor_displaycolor_service:service_manager { add };
dontaudit hal_graphics_composer_default vendor_displaycolor_service:service_manager { find };
dontaudit hal_graphics_composer_default vendor_surfaceflinger_vndservice:service_manager { add };
dontaudit hal_graphics_composer_default vendor_surfaceflinger_vndservice:service_manager { find };

View file

@ -0,0 +1,2 @@
# b/202906902
dontaudit hal_identity_citadel default_android_vndservice:service_manager { find };

View file

@ -0,0 +1,2 @@
# b/202907039
dontaudit hal_keymint_citadel default_android_vndservice:service_manager { find };

View file

@ -0,0 +1,2 @@
# b/202902683
dontaudit hal_secure_element_uicc hal_exynos_rild_hwservice:hwservice_manager { find };

View file

@ -0,0 +1,8 @@
# b/202906786
dontaudit hal_usb_impl configfs:lnk_file { create };
dontaudit hal_usb_impl configfs:lnk_file { read };
dontaudit hal_usb_impl hal_usb_gadget_hwservice:hwservice_manager { add };
dontaudit hal_usb_impl hal_usb_gadget_hwservice:hwservice_manager { find };
dontaudit hal_usb_impl hal_usb_hwservice:hwservice_manager { add };
dontaudit hal_usb_impl hal_usb_hwservice:hwservice_manager { find };
dontaudit hal_usb_impl hidl_base_hwservice:hwservice_manager { add };

View file

@ -0,0 +1,3 @@
# b/202906903
dontaudit hal_vibrator_default input_device:dir { open };
dontaudit hal_vibrator_default input_device:dir { read };

View file

@ -0,0 +1,9 @@
# b/202907040
dontaudit hal_weaver_citadel default_android_vndservice:service_manager { find };
dontaudit hal_weaver_citadel hal_authsecret_hwservice:hwservice_manager { add };
dontaudit hal_weaver_citadel hal_authsecret_hwservice:hwservice_manager { find };
dontaudit hal_weaver_citadel hal_oemlock_hwservice:hwservice_manager { add };
dontaudit hal_weaver_citadel hal_oemlock_hwservice:hwservice_manager { find };
dontaudit hal_weaver_citadel hal_weaver_hwservice:hwservice_manager { add };
dontaudit hal_weaver_citadel hal_weaver_hwservice:hwservice_manager { find };
dontaudit hal_weaver_citadel hidl_base_hwservice:hwservice_manager { add };

View file

@ -0,0 +1,2 @@
# b/202906904
dontaudit init_citadel default_android_vndservice:service_manager { find };

View file

@ -0,0 +1,4 @@
# b/202906901
dontaudit mediacodec_google hal_codec2_hwservice:hwservice_manager { add };
dontaudit mediacodec_google hal_codec2_hwservice:hwservice_manager { find };
dontaudit mediacodec_google hidl_base_hwservice:hwservice_manager { add };

View file

@ -0,0 +1,5 @@
# b/202906949
dontaudit mediacodec_samsung eco_service:service_manager { add };
dontaudit mediacodec_samsung hal_codec2_hwservice:hwservice_manager { add };
dontaudit mediacodec_samsung hal_codec2_hwservice:hwservice_manager { find };
dontaudit mediacodec_samsung hidl_base_hwservice:hwservice_manager { add };

View file

@ -0,0 +1,2 @@
# b/202906787
dontaudit platform_app hal_wlc_hwservice:hwservice_manager { find };

View file

@ -0,0 +1,2 @@
# b/202906772
dontaudit priv_app hal_exynos_rild_hwservice:hwservice_manager { find };

2
tracking_denials/rfsd.te Normal file
View file

@ -0,0 +1,2 @@
# b/202906886
dontaudit rfsd unlabeled:lnk_file { read };

2
tracking_denials/rild.te Normal file
View file

@ -0,0 +1,2 @@
# b/202907136
dontaudit rild unlabeled:lnk_file { read };

View file

@ -0,0 +1,2 @@
# b/202906997
dontaudit rlsservice rls_service:service_manager { add };

View file

@ -0,0 +1,2 @@
# b/202907037
dontaudit thermal_link_device sysfs:filesystem { associate };

View file

@ -0,0 +1,2 @@
# b/202906888
dontaudit vendor_ims_app hal_exynos_rild_hwservice:hwservice_manager { find };

View file

@ -0,0 +1,2 @@
# b/202907058
dontaudit vendor_rcs_app hal_exynos_rild_hwservice:hwservice_manager { find };

View file

@ -0,0 +1 @@
type hal_pixel_display_service, service_manager_type, vendor_service;

View file

@ -0,0 +1 @@
com.google.hardware.pixel.display.IDisplay/default u:object_r:hal_pixel_display_service:s0

View file

@ -1,2 +1,5 @@
type hal_power_stats_vendor_service, vndservice_manager_type;
type rls_service, vndservice_manager_type;
type vendor_displaycolor_service, vndservice_manager_type;
type vendor_surfaceflinger_vndservice, vndservice_manager_type;
type eco_service, vndservice_manager_type;

View file

@ -1 +1,4 @@
rlsservice u:object_r:rls_service:s0
displaycolor u:object_r:vendor_displaycolor_service:s0
Exynos.HWCService u:object_r:vendor_surfaceflinger_vndservice:s0
media.ecoservice u:object_r:eco_service:s0