diff --git a/tracking_denials/dumpstate.te b/tracking_denials/dumpstate.te index fe7e9e99..17756225 100644 --- a/tracking_denials/dumpstate.te +++ b/tracking_denials/dumpstate.te @@ -17,3 +17,7 @@ dontaudit dumpstate sysfs_scsi_devices_0000:file { read }; dontaudit dumpstate system_data_file:dir { open }; dontaudit dumpstate system_data_file:dir { read }; dontaudit dumpstate vold:binder { call }; +# b/262633248 +dontaudit dumpstate mediacodec_google:process { signal }; +dontaudit dumpstate mediacodec_samsung:process { signal }; +dontaudit dumpstate rild:binder { call }; diff --git a/tracking_denials/hal_power_default.te b/tracking_denials/hal_power_default.te index 1a97442a..760e2240 100644 --- a/tracking_denials/hal_power_default.te +++ b/tracking_denials/hal_power_default.te @@ -22,3 +22,11 @@ dontaudit hal_power_default sysfs:file { read }; dontaudit hal_power_default sysfs_display:file { getattr }; dontaudit hal_power_default sysfs_display:file { read }; dontaudit hal_power_default sysfs_fabric:file { getattr }; +# b/262633072 +dontaudit hal_power_default hal_power_default:capability { dac_read_search }; +dontaudit hal_power_default sysfs_camera:file { getattr }; +dontaudit hal_power_default sysfs_camera:file { read }; +dontaudit hal_power_default vendor_camera_prop:file { getattr }; +dontaudit hal_power_default vendor_camera_prop:file { map }; +dontaudit hal_power_default vendor_camera_prop:file { open }; +dontaudit hal_power_default vendor_camera_prop:file { read }; diff --git a/tracking_denials/mediacodec_google.te b/tracking_denials/mediacodec_google.te new file mode 100644 index 00000000..20392125 --- /dev/null +++ b/tracking_denials/mediacodec_google.te @@ -0,0 +1,2 @@ +# b/262633230 +dontaudit mediacodec_google vndbinder_device:chr_file { ioctl }; diff --git a/tracking_denials/mediacodec_samsung.te b/tracking_denials/mediacodec_samsung.te new file mode 100644 index 00000000..dc939ac6 --- /dev/null +++ b/tracking_denials/mediacodec_samsung.te @@ -0,0 +1,3 @@ +# b/262633502 +dontaudit mediacodec_samsung tombstoned:unix_stream_socket { connectto }; +dontaudit mediacodec_samsung tombstoned_crash_socket:sock_file { write }; diff --git a/tracking_denials/rild.te b/tracking_denials/rild.te new file mode 100644 index 00000000..123eebde --- /dev/null +++ b/tracking_denials/rild.te @@ -0,0 +1,2 @@ +# b/262633094 +dontaudit rild dumpstate:fd { use };