diff --git a/tracking_denials/con_monitor_app.te b/tracking_denials/con_monitor_app.te deleted file mode 100644 index 3baf986..0000000 --- a/tracking_denials/con_monitor_app.te +++ /dev/null @@ -1,36 +0,0 @@ -# b/261518779 -dontaudit con_monitor_app activity_service:service_manager { find }; -dontaudit con_monitor_app content_capture_service:service_manager { find }; -dontaudit con_monitor_app game_service:service_manager { find }; -dontaudit con_monitor_app netstats_service:service_manager { find }; -dontaudit con_monitor_app system_server:binder { call }; -dontaudit con_monitor_app system_server:binder { transfer }; -dontaudit con_monitor_app system_server:fd { use }; -# b/261783158 -dontaudit con_monitor_app system_file:file { getattr }; -dontaudit con_monitor_app system_file:file { map }; -dontaudit con_monitor_app system_file:file { open }; -dontaudit con_monitor_app system_file:file { read }; -dontaudit con_monitor_app tmpfs:file { execute }; -dontaudit con_monitor_app tmpfs:file { map }; -dontaudit con_monitor_app tmpfs:file { read }; -dontaudit con_monitor_app tmpfs:file { write }; -# b/261933171 -dontaudit con_monitor_app dumpstate:fd { use }; -dontaudit con_monitor_app dumpstate:fifo_file { append }; -dontaudit con_monitor_app dumpstate:fifo_file { write }; -dontaudit con_monitor_app system_server:fifo_file { write }; -dontaudit con_monitor_app tombstoned:unix_stream_socket { connectto }; -dontaudit con_monitor_app tombstoned_java_trace_socket:sock_file { write }; -# b/262455571 -dontaudit con_monitor_app data_file_type:dir { search }; -dontaudit con_monitor_app servicemanager:binder { call }; -dontaudit con_monitor_app statsd:unix_dgram_socket { sendto }; -dontaudit con_monitor_app statsdw_socket:sock_file { write }; -dontaudit con_monitor_app system_file:file { execute }; -# b/264489520 -userdebug_or_eng(` - permissive con_monitor_app; -') -# b/267843291 -dontaudit con_monitor_app resourcecache_data_file:file { read }; diff --git a/tracking_denials/dumpstate.te b/tracking_denials/dumpstate.te deleted file mode 100644 index 3313642..0000000 --- a/tracking_denials/dumpstate.te +++ /dev/null @@ -1,2 +0,0 @@ -# b/277155496 -dontaudit dumpstate default_android_service:service_manager { find }; diff --git a/tracking_denials/fastbootd.te b/tracking_denials/fastbootd.te deleted file mode 100644 index 4428b68..0000000 --- a/tracking_denials/fastbootd.te +++ /dev/null @@ -1,4 +0,0 @@ -# b/264489957 -userdebug_or_eng(` - permissive fastbootd; -') \ No newline at end of file diff --git a/tracking_denials/hal_sensors_default.te b/tracking_denials/hal_sensors_default.te deleted file mode 100644 index 601c2bb..0000000 --- a/tracking_denials/hal_sensors_default.te +++ /dev/null @@ -1,3 +0,0 @@ -# b/267260619 -dontaudit hal_sensors_default dumpstate:fd { use }; -dontaudit hal_sensors_default dumpstate:fifo_file { write }; diff --git a/tracking_denials/hal_usb_impl.te b/tracking_denials/hal_usb_impl.te deleted file mode 100644 index 08db477..0000000 --- a/tracking_denials/hal_usb_impl.te +++ /dev/null @@ -1,2 +0,0 @@ -# b/267261163 -dontaudit hal_usb_impl dumpstate:fd { use }; diff --git a/tracking_denials/incidentd.te b/tracking_denials/incidentd.te deleted file mode 100644 index 4bd4489..0000000 --- a/tracking_denials/incidentd.te +++ /dev/null @@ -1,3 +0,0 @@ -# b/261933310 -dontaudit incidentd debugfs_wakeup_sources:file { open }; -dontaudit incidentd debugfs_wakeup_sources:file { read }; diff --git a/tracking_denials/kernel.te b/tracking_denials/kernel.te deleted file mode 100644 index 23d091b..0000000 --- a/tracking_denials/kernel.te +++ /dev/null @@ -1,7 +0,0 @@ -# b/262794429 -dontaudit kernel sepolicy_file:file { getattr }; -dontaudit kernel system_bootstrap_lib_file:dir { getattr }; -dontaudit kernel system_bootstrap_lib_file:file { getattr }; -dontaudit kernel system_dlkm_file:dir { getattr }; -# b/263185161 -dontaudit kernel kernel:capability { net_bind_service }; diff --git a/tracking_denials/permissive.te b/tracking_denials/permissive.te index 34a6823..9fe4973 100644 --- a/tracking_denials/permissive.te +++ b/tracking_denials/permissive.te @@ -14,4 +14,8 @@ userdebug_or_eng(` permissive kernel; permissive hal_power_default; permissive servicemanager; + permissive con_monitor_app; + permissive systemui_app; + permissive ssr_detector_app; + permissive fastbootd; ') diff --git a/tracking_denials/rebalance_interrupts_vendor.te b/tracking_denials/rebalance_interrupts_vendor.te deleted file mode 100644 index f38b36f..0000000 --- a/tracking_denials/rebalance_interrupts_vendor.te +++ /dev/null @@ -1,2 +0,0 @@ -# b/260366278 -dontaudit rebalance_interrupts_vendor rebalance_interrupts_vendor:capability { dac_override }; diff --git a/tracking_denials/ssr_detector_app.te b/tracking_denials/ssr_detector_app.te deleted file mode 100644 index d1c8b73..0000000 --- a/tracking_denials/ssr_detector_app.te +++ /dev/null @@ -1,6 +0,0 @@ -# b/261651131 -dontaudit ssr_detector_app system_app_data_file:file { open }; -# b/264489567 -userdebug_or_eng(` - permissive ssr_detector_app; -') \ No newline at end of file diff --git a/tracking_denials/systemui_app.te b/tracking_denials/systemui_app.te deleted file mode 100644 index e4416d8..0000000 --- a/tracking_denials/systemui_app.te +++ /dev/null @@ -1,6 +0,0 @@ -# b/272628396 -#dontaudit systemui_app service_manager_type:service_manager find; -# b/294300348 -userdebug_or_eng(` - permissive systemui_app; -') diff --git a/tracking_denials/update_engine.te b/tracking_denials/update_engine.te deleted file mode 100644 index 0de59ee..0000000 --- a/tracking_denials/update_engine.te +++ /dev/null @@ -1,2 +0,0 @@ -# b/267261048 -dontaudit update_engine dumpstate:fd { use }; diff --git a/tracking_denials/vendor_init.te b/tracking_denials/vendor_init.te deleted file mode 100644 index abfba26..0000000 --- a/tracking_denials/vendor_init.te +++ /dev/null @@ -1,3 +0,0 @@ -# b/260366195 -dontaudit vendor_init debugfs_trace_marker:file { getattr }; -dontaudit vendor_init vendor_init:capability2 { block_suspend };