diff --git a/tracking_denials/con_monitor_app.te b/tracking_denials/con_monitor_app.te index e22d3c6d..4454bfdb 100644 --- a/tracking_denials/con_monitor_app.te +++ b/tracking_denials/con_monitor_app.te @@ -22,3 +22,9 @@ dontaudit con_monitor_app dumpstate:fifo_file { write }; dontaudit con_monitor_app system_server:fifo_file { write }; dontaudit con_monitor_app tombstoned:unix_stream_socket { connectto }; dontaudit con_monitor_app tombstoned_java_trace_socket:sock_file { write }; +# b/262455571 +dontaudit con_monitor_app data_file_type:dir { search }; +dontaudit con_monitor_app servicemanager:binder { call }; +dontaudit con_monitor_app statsd:unix_dgram_socket { sendto }; +dontaudit con_monitor_app statsdw_socket:sock_file { write }; +dontaudit con_monitor_app system_file:file { execute }; diff --git a/tracking_denials/euiccpixel_app.te b/tracking_denials/euiccpixel_app.te index cb4a9f6d..fdddd335 100644 --- a/tracking_denials/euiccpixel_app.te +++ b/tracking_denials/euiccpixel_app.te @@ -61,3 +61,5 @@ dontaudit euiccpixel_app dumpstate:fifo_file { write }; dontaudit euiccpixel_app system_server:fifo_file { write }; dontaudit euiccpixel_app tombstoned:unix_stream_socket { connectto }; dontaudit euiccpixel_app tombstoned_java_trace_socket:sock_file { write }; +# b/262451641 +dontaudit euiccpixel_app permission_checker_service:service_manager { find }; diff --git a/tracking_denials/google_camera_app.te b/tracking_denials/google_camera_app.te index 51e2d710..bfb0444d 100644 --- a/tracking_denials/google_camera_app.te +++ b/tracking_denials/google_camera_app.te @@ -3,3 +3,19 @@ dontaudit google_camera_app vendor_file:file { getattr }; dontaudit google_camera_app vendor_file:file { map }; dontaudit google_camera_app vendor_file:file { open }; dontaudit google_camera_app vendor_file:file { read }; +# b/262455755 +dontaudit google_camera_app activity_service:service_manager { find }; +dontaudit google_camera_app cameraserver_service:service_manager { find }; +dontaudit google_camera_app content_capture_service:service_manager { find }; +dontaudit google_camera_app device_state_service:service_manager { find }; +dontaudit google_camera_app edgetpu_app_service:service_manager { find }; +dontaudit google_camera_app edgetpu_device:chr_file { ioctl }; +dontaudit google_camera_app edgetpu_device:chr_file { map }; +dontaudit google_camera_app edgetpu_device:chr_file { read write }; +dontaudit google_camera_app fwk_stats_service:service_manager { find }; +dontaudit google_camera_app game_service:service_manager { find }; +dontaudit google_camera_app mediaserver_service:service_manager { find }; +dontaudit google_camera_app netstats_service:service_manager { find }; +dontaudit google_camera_app sensorservice_service:service_manager { find }; +dontaudit google_camera_app surfaceflinger_service:service_manager { find }; +dontaudit google_camera_app thermal_service:service_manager { find }; diff --git a/tracking_denials/hal_wifi_ext.te b/tracking_denials/hal_wifi_ext.te new file mode 100644 index 00000000..cde3a01c --- /dev/null +++ b/tracking_denials/hal_wifi_ext.te @@ -0,0 +1,2 @@ +# b/262455388 +dontaudit hal_wifi_ext grilservice_app:binder { call }; diff --git a/tracking_denials/hal_wlc.te b/tracking_denials/hal_wlc.te index c3afb322..35fcf30b 100644 --- a/tracking_denials/hal_wlc.te +++ b/tracking_denials/hal_wlc.te @@ -3,3 +3,15 @@ dontaudit hal_wlc sysfs:file { getattr }; dontaudit hal_wlc sysfs:file { open }; dontaudit hal_wlc sysfs:file { read }; dontaudit hal_wlc sysfs:file { write }; +# b/262455719 +dontaudit hal_wlc hal_wlc:netlink_kobject_uevent_socket { bind }; +dontaudit hal_wlc hal_wlc:netlink_kobject_uevent_socket { create }; +dontaudit hal_wlc hal_wlc:netlink_kobject_uevent_socket { getopt }; +dontaudit hal_wlc hal_wlc:netlink_kobject_uevent_socket { read }; +dontaudit hal_wlc hal_wlc:netlink_kobject_uevent_socket { setopt }; +dontaudit hal_wlc hwservicemanager:binder { call }; +dontaudit hal_wlc hwservicemanager:binder { transfer }; +dontaudit hal_wlc hwservicemanager_prop:file { getattr }; +dontaudit hal_wlc hwservicemanager_prop:file { map }; +dontaudit hal_wlc hwservicemanager_prop:file { open }; +dontaudit hal_wlc hwservicemanager_prop:file { read }; diff --git a/tracking_denials/priv_app.te b/tracking_denials/priv_app.te index 19f9af87..8312d43e 100644 --- a/tracking_denials/priv_app.te +++ b/tracking_denials/priv_app.te @@ -18,3 +18,5 @@ dontaudit priv_app vendor_file:file { getattr }; dontaudit priv_app vendor_file:file { map }; dontaudit priv_app vendor_file:file { open }; dontaudit priv_app vendor_file:file { read }; +# b/262455954 +dontaudit priv_app euiccpixel_app:binder { call }; diff --git a/tracking_denials/system_server.te b/tracking_denials/system_server.te index 7b5f543e..7ef08827 100644 --- a/tracking_denials/system_server.te +++ b/tracking_denials/system_server.te @@ -14,3 +14,5 @@ dontaudit system_server hal_usb_gadget_impl:binder { call }; dontaudit system_server hal_usb_gadget_impl:binder { transfer }; dontaudit system_server hal_usb_impl:binder { call }; dontaudit system_server hal_usb_impl:binder { transfer }; +# b/262455682 +dontaudit system_server con_monitor_app:process { setsched };