clone sepolicy from gs101

s/gs101/gs201/g

Bug: 186836335
Test: Boot
Signed-off-by: Pat Tjin <pattjin@google.com>
Change-Id: Ifa0d083f7317c38eb02c8228c2804cbd4d5ee19f
This commit is contained in:
Pat Tjin 2021-05-20 17:51:26 -07:00
parent 703587e97c
commit d3a63de64b
172 changed files with 3678 additions and 0 deletions

59
private/dex2oat.te Normal file
View file

@ -0,0 +1,59 @@
# b/187016929
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat proc_filesystems:file read ;
dontaudit dex2oat postinstall_apex_mnt_dir:file getattr ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat proc_filesystems:file read ;
dontaudit dex2oat postinstall_apex_mnt_dir:file getattr ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;
dontaudit dex2oat vendor_overlay_file:file read ;

2
private/gmscore_app.te Normal file
View file

@ -0,0 +1,2 @@
# b/177389198
dontaudit gmscore_app adbd_prop:file *;

View file

@ -0,0 +1,2 @@
# b/176868217
dontaudit hal_dumpstate adbd_prop:file *;

14
private/incidentd.te Normal file
View file

@ -0,0 +1,14 @@
# b/174961589
dontaudit incidentd adbd_config_prop:file open ;
dontaudit incidentd adbd_prop:file getattr ;
dontaudit incidentd adbd_prop:file open ;
dontaudit incidentd adbd_config_prop:file open ;
dontaudit incidentd adbd_config_prop:file getattr ;
dontaudit incidentd adbd_config_prop:file map ;
dontaudit incidentd adbd_prop:file open ;
dontaudit incidentd adbd_prop:file getattr ;
dontaudit incidentd adbd_prop:file map ;
dontaudit incidentd apexd_prop:file open ;
dontaudit incidentd adbd_config_prop:file getattr ;
dontaudit incidentd adbd_config_prop:file map ;
dontaudit incidentd adbd_prop:file map ;

7
private/lpdumpd.te Normal file
View file

@ -0,0 +1,7 @@
# b/177176997
dontaudit lpdumpd block_device:blk_file getattr ;
dontaudit lpdumpd block_device:blk_file getattr ;
dontaudit lpdumpd block_device:blk_file read ;
dontaudit lpdumpd block_device:blk_file getattr ;
dontaudit lpdumpd block_device:blk_file read ;
dontaudit lpdumpd block_device:blk_file read ;

19
private/priv_app.te Normal file
View file

@ -0,0 +1,19 @@
# b/178433525
dontaudit priv_app adbd_prop:file { map };
dontaudit priv_app adbd_prop:file { getattr };
dontaudit priv_app adbd_prop:file { open };
dontaudit priv_app ab_update_gki_prop:file { map };
dontaudit priv_app ab_update_gki_prop:file { getattr };
dontaudit priv_app ab_update_gki_prop:file { open };
dontaudit priv_app aac_drc_prop:file { map };
dontaudit priv_app aac_drc_prop:file { getattr };
dontaudit priv_app aac_drc_prop:file { open };
dontaudit priv_app adbd_prop:file { map };
dontaudit priv_app aac_drc_prop:file { open };
dontaudit priv_app aac_drc_prop:file { getattr };
dontaudit priv_app aac_drc_prop:file { map };
dontaudit priv_app ab_update_gki_prop:file { open };
dontaudit priv_app ab_update_gki_prop:file { getattr };
dontaudit priv_app ab_update_gki_prop:file { map };
dontaudit priv_app adbd_prop:file { open };
dontaudit priv_app adbd_prop:file { getattr };

1
private/radio.te Normal file
View file

@ -0,0 +1 @@
add_service(radio, uce_service)

1
private/service_contexts Normal file
View file

@ -0,0 +1 @@
telephony.oem.oemrilhook u:object_r:radio_service:s0

View file

@ -0,0 +1,2 @@
# b/177389321
dontaudit untrusted_app_25 adbd_prop:file *;

View file

@ -0,0 +1,2 @@
# b/188114822
dontaudit wait_for_keymaster servicemanager:binder transfer;