diff --git a/tracking_denials/system_server.te b/tracking_denials/system_server.te index d79b5637..c2dddb76 100644 --- a/tracking_denials/system_server.te +++ b/tracking_denials/system_server.te @@ -23,3 +23,5 @@ dontaudit system_server mediacodec_samsung:binder { call }; dontaudit system_server mediacodec_samsung:binder { transfer }; # b/263184920 dontaudit system_server hal_camera_default:binder { transfer }; +# b/263305107 +dontaudit system_server hal_camera_default:binder { call }; diff --git a/tracking_denials/system_suspend.te b/tracking_denials/system_suspend.te index 26e48255..c9a3f336 100644 --- a/tracking_denials/system_suspend.te +++ b/tracking_denials/system_suspend.te @@ -11,3 +11,5 @@ dontaudit system_suspend_server sysfs_aoc:file { open }; dontaudit system_suspend_server sysfs_aoc:file { read }; # b/261105356 dontaudit system_suspend_server chre:binder { transfer }; +# b/263305203 +dontaudit system_suspend_server tee:binder { transfer }; diff --git a/tracking_denials/tee.te b/tracking_denials/tee.te new file mode 100644 index 00000000..33f21e20 --- /dev/null +++ b/tracking_denials/tee.te @@ -0,0 +1,18 @@ +# b/263304957 +dontaudit tee gsi_metadata_file:dir { search }; +dontaudit tee hal_system_suspend_service:service_manager { find }; +dontaudit tee init:unix_stream_socket { connectto }; +dontaudit tee metadata_file:dir { search }; +dontaudit tee mnt_vendor_file:dir { search }; +dontaudit tee persist_file:dir { search }; +dontaudit tee persist_ss_file:dir { search }; +dontaudit tee persist_ss_file:file { open }; +dontaudit tee persist_ss_file:file { read write }; +dontaudit tee property_socket:sock_file { write }; +dontaudit tee servicemanager:binder { call }; +dontaudit tee sg_device:chr_file { ioctl }; +dontaudit tee sg_device:chr_file { open }; +dontaudit tee sg_device:chr_file { read write }; +dontaudit tee system_suspend_server:binder { call }; +dontaudit tee tee_data_file:lnk_file { read }; +dontaudit tee vendor_trusty_storage_prop:property_service { set }; diff --git a/tracking_denials/trusty_apploader.te b/tracking_denials/trusty_apploader.te new file mode 100644 index 00000000..c756f42a --- /dev/null +++ b/tracking_denials/trusty_apploader.te @@ -0,0 +1,7 @@ +# b/263305034 +dontaudit trusty_apploader dmabuf_system_heap_device:chr_file { ioctl }; +dontaudit trusty_apploader dmabuf_system_heap_device:chr_file { open }; +dontaudit trusty_apploader dmabuf_system_heap_device:chr_file { read }; +dontaudit trusty_apploader tee_device:chr_file { ioctl }; +dontaudit trusty_apploader tee_device:chr_file { open }; +dontaudit trusty_apploader tee_device:chr_file { read write }; diff --git a/tracking_denials/vendor_init.te b/tracking_denials/vendor_init.te index 2caca382..4905e0d4 100644 --- a/tracking_denials/vendor_init.te +++ b/tracking_denials/vendor_init.te @@ -9,3 +9,5 @@ dontaudit vendor_init bootdevice_sysdev:file { create }; dontaudit vendor_init modem_img_file:filesystem { getattr }; dontaudit vendor_init proc_dirty:file { write }; dontaudit vendor_init proc_sched:file { write }; +# b/263305106 +dontaudit vendor_init vendor_battery_defender_prop:property_service { set }; diff --git a/tracking_denials/vold.te b/tracking_denials/vold.te new file mode 100644 index 00000000..49aa3a0d --- /dev/null +++ b/tracking_denials/vold.te @@ -0,0 +1,2 @@ +# b/263305225 +dontaudit vold sysfs_scsi_devices_0000:file { write };