diff --git a/legacy/whitechapel_pro/file.te b/legacy/whitechapel_pro/file.te deleted file mode 100644 index 786e5f4..0000000 --- a/legacy/whitechapel_pro/file.te +++ /dev/null @@ -1,25 +0,0 @@ -# Data -type updated_wifi_firmware_data_file, file_type, data_file_type; -type vendor_misc_data_file, file_type, data_file_type; -type per_boot_file, file_type, data_file_type, core_data_file_type; -type powerstats_vendor_data_file, file_type, data_file_type; - -# sysfs -type bootdevice_sysdev, dev_type; -type sysfs_wifi, sysfs_type, fs_type; -type sysfs_bcmdhd, sysfs_type, fs_type; -type sysfs_chargelevel, sysfs_type, fs_type; -type sysfs_camera, sysfs_type, fs_type; - -# persist -type persist_ss_file, file_type, vendor_persist_type; - -# Storage Health HAL -type proc_f2fs, proc_type, fs_type; - -# Vendor tools -type vendor_dumpsys, vendor_file_type, file_type; - -# USB-C throttling stats -type sysfs_usbc_throttling_stats, sysfs_type, fs_type; - diff --git a/legacy/zuma/vendor/file.te b/legacy/zuma/vendor/file.te deleted file mode 100644 index ad6451b..0000000 --- a/legacy/zuma/vendor/file.te +++ /dev/null @@ -1,53 +0,0 @@ -# persist -type persist_display_file, file_type, vendor_persist_type; -type persist_battery_file, file_type, vendor_persist_type; -type persist_camera_file, file_type, vendor_persist_type; -type persist_fingerprint_file, file_type, vendor_persist_type; - -#sysfs -type sysfs_power_dump, sysfs_type, fs_type; -type sysfs_acpm_stats, sysfs_type, fs_type; -type sysfs_write_leds, sysfs_type, fs_type; - -# Trusty -type sysfs_trusty, sysfs_type, fs_type; - -# mount FS -allow proc_vendor_sched proc:filesystem associate; -allow bootdevice_sysdev sysfs:filesystem associate; - -# debugfs -type vendor_charger_debugfs, fs_type, debugfs_type; -type vendor_votable_debugfs, fs_type, debugfs_type; -type vendor_battery_debugfs, fs_type, debugfs_type; -type vendor_pm_genpd_debugfs, fs_type, debugfs_type; -type vendor_maxfg_debugfs, fs_type, debugfs_type; - -# WLC -type sysfs_wlc, sysfs_type, fs_type; - -# CHRE -type chre_socket, file_type; - -# BT -type vendor_bt_data_file, file_type, data_file_type; - -# Data -type chre_data_file, file_type, data_file_type; -type vendor_fingerprint_data_file, file_type, data_file_type; - -# Vendor sched files -userdebug_or_eng(` - typeattribute proc_vendor_sched mlstrustedobject; -') - -# sysfs -type sysfs_fabric, sysfs_type, fs_type; -type sysfs_em_profile, sysfs_type, fs_type; -type sysfs_ota, sysfs_type, fs_type; - -# GSA -type sysfs_gsa_log, sysfs_type, fs_type; - -# Faceauth -type sysfs_faceauth_rawimage_heap, sysfs_type, fs_type; diff --git a/tracking_denials/file.te b/tracking_denials/file.te new file mode 100644 index 0000000..6a2f6b2 --- /dev/null +++ b/tracking_denials/file.te @@ -0,0 +1,14 @@ +# b/314035704 +# Data +type per_boot_file, file_type, data_file_type, core_data_file_type; + +# sysfs +type sysfs_bcmdhd, sysfs_type, fs_type; +type sysfs_chargelevel, sysfs_type, fs_type; + +# mount FS +allow proc_vendor_sched proc:filesystem associate; + +# Faceauth +type sysfs_faceauth_rawimage_heap, sysfs_type, fs_type; + diff --git a/vendor/file.te b/vendor/file.te index 57c19a9..b221f7b 100644 --- a/vendor/file.te +++ b/vendor/file.te @@ -1,15 +1,70 @@ # persist type persist_uwb_file, file_type, vendor_persist_type; +type persist_ss_file, file_type, vendor_persist_type; +type persist_display_file, file_type, vendor_persist_type; +type persist_battery_file, file_type, vendor_persist_type; +type persist_camera_file, file_type, vendor_persist_type; +type persist_fingerprint_file, file_type, vendor_persist_type; #sysfs type sysfs_pca, sysfs_type, fs_type; +type bootdevice_sysdev, dev_type; +type sysfs_wifi, sysfs_type, fs_type; +type sysfs_camera, sysfs_type, fs_type; +type sysfs_power_dump, sysfs_type, fs_type; +type sysfs_acpm_stats, sysfs_type, fs_type; +type sysfs_write_leds, sysfs_type, fs_type; +type sysfs_fabric, sysfs_type, fs_type; +type sysfs_em_profile, sysfs_type, fs_type; +type sysfs_ota, sysfs_type, fs_type; type sysfs_ospm, sysfs_type, fs_type; # debugfs type vendor_regmap_debugfs, fs_type, debugfs_type; type vendor_usb_debugfs, fs_type, debugfs_type; +type vendor_charger_debugfs, fs_type, debugfs_type; +type vendor_votable_debugfs, fs_type, debugfs_type; +type vendor_battery_debugfs, fs_type, debugfs_type; +type vendor_pm_genpd_debugfs, fs_type, debugfs_type; +type vendor_maxfg_debugfs, fs_type, debugfs_type; # Data type uwb_vendor_data_file, file_type, data_file_type, app_data_file_type; type uwb_data_vendor, file_type, data_file_type; +type updated_wifi_firmware_data_file, file_type, data_file_type; +type vendor_misc_data_file, file_type, data_file_type; +type powerstats_vendor_data_file, file_type, data_file_type; +type chre_data_file, file_type, data_file_type; +type vendor_fingerprint_data_file, file_type, data_file_type; +# Storage Health HAL +type proc_f2fs, proc_type, fs_type; + +# Vendor tools +type vendor_dumpsys, vendor_file_type, file_type; + +# USB-C throttling stats +type sysfs_usbc_throttling_stats, sysfs_type, fs_type; + +# Trusty +type sysfs_trusty, sysfs_type, fs_type; + +# mount FS +allow bootdevice_sysdev sysfs:filesystem associate; + +# WLC +type sysfs_wlc, sysfs_type, fs_type; + +# CHRE +type chre_socket, file_type; + +# BT +type vendor_bt_data_file, file_type, data_file_type; + +# Vendor sched files +userdebug_or_eng(` + typeattribute proc_vendor_sched mlstrustedobject; +') + +# GSA +type sysfs_gsa_log, sysfs_type, fs_type;