Update error on ROM 9409984

Bug: 262794634
Bug: 262793919
Bug: 262794428
Bug: 262794938
Bug: 262794359
Bug: 262794939
Bug: 262793920
Bug: 262794577
Bug: 262794578
Bug: 262794969
Bug: 262794970
Bug: 262794360
Bug: 262794429
Test: scanAvcDeniedLogRightAfterReboot
Change-Id: Iaa3d4e54ccee70f48a322df6d229d3cae1ba1df6
This commit is contained in:
Adam Shih 2022-12-16 09:26:05 +08:00
parent 3406af9012
commit 81112ab63a
13 changed files with 77 additions and 0 deletions

View file

@ -21,3 +21,5 @@ dontaudit hal_health_default vendor_battery_defender_prop:property_service { set
dontaudit hal_health_default dumpstate:fd { use };
# b/262178574
dontaudit hal_health_default dumpstate:fifo_file { write };
# b/262794970
dontaudit hal_health_default sysfs_batteryinfo:file { write };

View file

@ -1,2 +1,5 @@
# b/262455388
dontaudit hal_wifi_ext grilservice_app:binder { call };
# b/262794359
dontaudit hal_wifi_ext updated_wifi_firmware_data_file:dir { search };
dontaudit hal_wifi_ext vendor_wifi_version:property_service { set };

View file

@ -0,0 +1,2 @@
# b/262794939
dontaudit hbmsvmanager_app hal_pixel_display_service:service_manager { find };

4
tracking_denials/init.te Normal file
View file

@ -0,0 +1,4 @@
# b/262794360
dontaudit init ram_device:blk_file { write };
dontaudit init sysfs_scsi_devices_0000:file { open };
dontaudit init sysfs_scsi_devices_0000:file { write };

View file

@ -10,3 +10,11 @@ dontaudit kernel vendor_regmap_debugfs:dir { search };
dontaudit kernel vendor_battery_debugfs:dir { search };
# b/261933155
dontaudit kernel vendor_fw_file:file { getattr };
# b/262794429
dontaudit kernel same_process_hal_file:file { getattr };
dontaudit kernel sepolicy_file:file { getattr };
dontaudit kernel system_bootstrap_lib_file:dir { getattr };
dontaudit kernel system_bootstrap_lib_file:file { getattr };
dontaudit kernel system_dlkm_file:dir { getattr };
dontaudit kernel vendor_fw_file:dir { getattr };
dontaudit kernel vendor_fw_file:dir { read };

View file

@ -1,2 +1,17 @@
# b/262633230
dontaudit mediacodec_google vndbinder_device:chr_file { ioctl };
# b/262793920
dontaudit mediacodec_google dmabuf_system_heap_device:chr_file { getattr };
dontaudit mediacodec_google hwservicemanager:binder { call };
dontaudit mediacodec_google hwservicemanager:binder { transfer };
dontaudit mediacodec_google hwservicemanager_prop:file { getattr };
dontaudit mediacodec_google hwservicemanager_prop:file { map };
dontaudit mediacodec_google hwservicemanager_prop:file { open };
dontaudit mediacodec_google hwservicemanager_prop:file { read };
dontaudit mediacodec_google mediaserver:binder { transfer };
dontaudit mediacodec_google platform_app:binder { transfer };
dontaudit mediacodec_google system_server:binder { transfer };
dontaudit mediacodec_google vndbinder_device:chr_file { map };
dontaudit mediacodec_google vndbinder_device:chr_file { open };
dontaudit mediacodec_google vndbinder_device:chr_file { read };
dontaudit mediacodec_google vndbinder_device:chr_file { write };

View file

@ -1,3 +1,24 @@
# b/262633502
dontaudit mediacodec_samsung tombstoned:unix_stream_socket { connectto };
dontaudit mediacodec_samsung tombstoned_crash_socket:sock_file { write };
# b/262794634
dontaudit mediacodec_samsung dmabuf_system_heap_device:chr_file { getattr };
dontaudit mediacodec_samsung eco_service:service_manager { add };
dontaudit mediacodec_samsung hwservicemanager:binder { call };
dontaudit mediacodec_samsung hwservicemanager:binder { transfer };
dontaudit mediacodec_samsung hwservicemanager_prop:file { getattr };
dontaudit mediacodec_samsung hwservicemanager_prop:file { map };
dontaudit mediacodec_samsung hwservicemanager_prop:file { open };
dontaudit mediacodec_samsung hwservicemanager_prop:file { read };
dontaudit mediacodec_samsung appdomain:binder { transfer };
dontaudit mediacodec_samsung mediaserver:binder { transfer };
dontaudit mediacodec_samsung mediaswcodec:binder { transfer };
dontaudit mediacodec_samsung platform_app:binder { transfer };
dontaudit mediacodec_samsung system_server:binder { transfer };
dontaudit mediacodec_samsung vndbinder_device:chr_file { ioctl };
dontaudit mediacodec_samsung vndbinder_device:chr_file { map };
dontaudit mediacodec_samsung vndbinder_device:chr_file { open };
dontaudit mediacodec_samsung vndbinder_device:chr_file { read };
dontaudit mediacodec_samsung vndbinder_device:chr_file { write };
dontaudit mediacodec_samsung vndservicemanager:binder { call };
dontaudit mediacodec_samsung vndservicemanager:binder { transfer };

View file

@ -0,0 +1,3 @@
# b/262793919
dontaudit appdomain mediacodec_samsung:binder { call };
dontaudit appdomain mediacodec_samsung:binder { transfer };

View file

@ -0,0 +1,3 @@
# b/262794577
dontaudit mediaserver mediacodec_google:binder { call };
dontaudit mediaserver mediacodec_samsung:binder { call };

View file

@ -0,0 +1,2 @@
# b/262794578
dontaudit mediaswcodec mediacodec_samsung:binder { call };

View file

@ -2,3 +2,10 @@
dontaudit platform_app default_android_service:service_manager { find };
# b/260922162
dontaudit platform_app default_android_service:service_manager { find };
# b/262794428
dontaudit platform_app hal_wlc:binder { call };
dontaudit platform_app hal_wlc:binder { transfer };
dontaudit platform_app mediacodec_google:binder { call };
dontaudit platform_app mediacodec_google:binder { transfer };
dontaudit platform_app mediacodec_samsung:binder { call };
dontaudit platform_app mediacodec_samsung:binder { transfer };

View file

@ -10,3 +10,5 @@ dontaudit secure_element system_data_file:dir { remove_name };
dontaudit secure_element system_data_file:file { create };
dontaudit secure_element system_data_file:file { rename };
dontaudit secure_element system_data_file:file { write open };
# b/262794969
dontaudit secure_element system_data_file:file { unlink };

View file

@ -16,3 +16,8 @@ dontaudit system_server hal_usb_impl:binder { call };
dontaudit system_server hal_usb_impl:binder { transfer };
# b/262455682
dontaudit system_server con_monitor_app:process { setsched };
# b/262794938
dontaudit system_server mediacodec_google:binder { call };
dontaudit system_server mediacodec_google:binder { transfer };
dontaudit system_server mediacodec_samsung:binder { call };
dontaudit system_server mediacodec_samsung:binder { transfer };