Initial TWRP device tree for sycamore_row_5G

This commit is contained in:
Nicholas Andrew 2026-08-31 00:39:29 -04:00
commit 11a5d1b7a6
50 changed files with 1777 additions and 144 deletions

View file

@ -0,0 +1,2 @@
# R7v9.60: dynamic twrp.user.<id>.decrypt state
twrp.user. u:object_r:twrp_user_decrypt_prop:s0

View file

@ -0,0 +1,3 @@
# R7v9.60: TWRP per-user FBE state shared by vold and recovery.
system_public_prop(twrp_user_decrypt_prop)

View file

@ -8,3 +8,19 @@
/dev/0:0:0:49476 u:object_r:teei_rpmb_device:s0
/dev/rpmb0 u:object_r:teei_rpmb_device:s0
/dev/utr_tui u:object_r:utr_tui_device:s0
# Physical misc partition backing /dev/block/by-name/misc.
/dev/block/sdc1 u:object_r:misc_block_device:s0
/dev/dri/card0 u:object_r:graphics_device:s0
# Physical userdata partition.
/dev/block/sdc73 u:object_r:userdata_block_device:s0
# Stock Beanpod KeyMint HAL copied into the recovery ramdisk.
# Label only this executable so it can run in the native KeyMint HAL domain.
/vendor/bin/hw/android\.hardware\.security\.keymint@2\.0-service\.beanpod u:object_r:hal_keymint_default_exec:s0
# Recovery-only crypto helper. Recovery cpio starts as rootfs, so init uses an
# explicit native-vold seclabel; this exact mapping documents its intended type.
/system/bin/sycamore_fscryptd u:object_r:vold_exec:s0

9
sepolicy/vendor/genfs_contexts vendored Normal file
View file

@ -0,0 +1,9 @@
# Sycamore power-supply sysfs consumed by the recovery Health HAL.
#
# AOSP Health policy grants hal_health_server access to sysfs_batteryinfo.
# Keep these labels device-specific rather than granting generic sysfs access.
genfscon sysfs /devices/platform/soc/11b20000.i2c/i2c-3/3-0055/power_supply/battery u:object_r:sysfs_batteryinfo:s0
genfscon sysfs /devices/platform/soc/11b20000.i2c/i2c-3/3-001a/power_supply/charger u:object_r:sysfs_batteryinfo:s0
genfscon sysfs /devices/platform/charger/power_supply/mtk-master-charger u:object_r:sysfs_batteryinfo:s0
genfscon sysfs /devices/platform/charger/power_supply/mtk-slave-charger u:object_r:sysfs_batteryinfo:s0

35
sepolicy/vendor/sycamore_bootctl.te vendored Normal file
View file

@ -0,0 +1,35 @@
# Dedicated recovery BootControl HAL domain. Do not attach the HAL server
# attributes to the much broader recovery domain.
type sycamore_bootctl, domain;
hal_server_domain(sycamore_bootctl, hal_bootctl)
# Recovery-cpio files all retain rootfs. The service's explicit seclabel selects
# this transition; domain_trans supplies init transition plus entrypoint/read/map
# access for the executable, linker, implementation, and shared libraries. It
# deliberately does not grant execute_no_trans.
domain_trans(init, rootfs, sycamore_bootctl)
# libhardware searches rootfs-backed system/vendor hw directories for the
# MTK BootControl implementation. Recovery cpio directories retain rootfs.
allow sycamore_bootctl rootfs:dir { read open getattr search };
# MTK BootControl initialization: observed enforcing AVCs after the
# implementation library became reachable.
allow sycamore_bootctl proc_cmdline:file { read open getattr };
allow sycamore_bootctl sysfs_dt_firmware_android:dir search;
allow sycamore_bootctl block_device:dir search;
allow sycamore_bootctl metadata_file:dir search;
allow sycamore_bootctl sycamore_recovery_metadata_file:dir search;
# MTK BootControl reads the Android DT compatible node during initialization.
allow sycamore_bootctl sysfs_dt_firmware_android:file { read open getattr };
# fs_mgr's recovery fstab reader probes the DSU/GSI boot indicator.
# Directory search is required so a nonexistent indicator returns ENOENT
# rather than EACCES, which ReadFstabFromFile treats as fatal.
allow sycamore_bootctl gsi_metadata_file:dir search;
# BootControl reads/writes the A/B bootloader control and Virtual A/B
# metadata stored in the misc partition. The physical device is labeled
# misc_block_device by the device-specific file_contexts rule.
allow sycamore_bootctl misc_block_device:blk_file rw_file_perms;

85
sepolicy/vendor/sycamore_fscryptd.te vendored Normal file
View file

@ -0,0 +1,85 @@
# sycamore_fscryptd is staged in recovery cpio but deliberately runs in vold's
# native domain. Grant only immutable rootfs entrypoint/runtime access and the
# private recovery-to-vold Unix-socket connection.
recovery_only(`
allow vold rootfs:file { entrypoint execute getattr open read map };
allow vold rootfs:dir { getattr search open read };
# fs_mgr ReadDefaultFstab probes recovery-mounted metadata/DSU state.
# /metadata is forced to sycamore_recovery_metadata_file in recovery.
allow vold sycamore_recovery_metadata_file:dir search;
# TWRP KeyStorage stages an upgraded KeyMint blob under /tmp/keymaster_key_blob.
# The file is created earlier by recovery metadata decrypt; native vold only
# needs the demonstrated write permission when systemwide fscrypt reuses it.
allow vold tmpfs:file { open write };
allow recovery vold:unix_stream_socket connectto;
')
# R7v9.41: recovery-cpio linker64 remains rootfs; permit only ELF mapping
allow vold_prepare_subdirs rootfs:file { execute getattr map open read };
allow hal_gatekeeper_default rootfs:file { execute getattr map open read };
allow vold_prepare_subdirs rootfs:dir read;
# R7v9.51: complete stock-style read-side SQLite access to locksettings.db
allow recovery system_data_file:file { getattr ioctl lock open read };
# R7v9.58: Gatekeeper recovery-rootfs HAL/library directory enumeration
allow hal_gatekeeper_default rootfs:dir { open read };
# R7v9.60: TWRP per-user FBE state published by vold and consumed by recovery.
# Without this property, Parse_Users() skips locked user 0 entirely.
set_prop(vold, twrp_user_decrypt_prop)
get_prop(recovery, twrp_user_decrypt_prop)
set_prop(recovery, twrp_user_decrypt_prop)
# R7v9.61: recovery is a client of the already-running Gatekeeper HAL
# for synthetic-password credential verification.
hal_client_domain(recovery, hal_gatekeeper)
# R7v9.62: Beanpod Gatekeeper credential verification talks to
# /dev/isee_tee0, labeled teei_client_device in recovery.
allow hal_gatekeeper_default teei_client_device:chr_file { ioctl map open read write };
# R7v9.66: recovery submits the Gatekeeper HardwareAuthToken to
# Keystore2's android.security.authorization AIDL service.
allow recovery authorization_service:service_manager find;
# R7v9.69: Keystore2 operates SQLite's recovery-side persistent database
# plus its journal/WAL/SHM sidecars under /tmp/misc/keystore.
#
# This is one logical SQLite lifecycle permission set rather than one
# permission-per-flash debugging.
allow keystore tmpfs:dir {
add_name
getattr
open
read
remove_name
search
write
};
allow keystore tmpfs:file {
create
getattr
ioctl
lock
map
open
read
setattr
unlink
write
};
# R7v9.70: Android SQLite probes the backing filesystem with ioctl 0xf50c.
# Ordinary ioctl permission does not authorize command-specific xperms.
allowxperm keystore tmpfs:file ioctl 0xf50c;
# R7v9.69: recovery submits the Gatekeeper-generated HardwareAuthToken
# through android.security.authorization to Keystore2.
allow recovery keystore:keystore2 add_auth;

23
sepolicy/vendor/sycamore_health.te vendored Normal file
View file

@ -0,0 +1,23 @@
# Dedicated recovery Health HAL domain. Do not attach hal_health_server
# to the broad recovery domain.
type sycamore_health, domain;
hal_server_domain(sycamore_health, hal_health)
# Recovery-cpio executables retain the rootfs label. The service's explicit
# seclabel selects this domain; domain_trans supplies init transition and
# executable entrypoint access.
domain_trans(init, rootfs, sycamore_health)
# Recovery cpio directories retain rootfs. Health's passthrough loader must
# traverse /system and its hw-library paths to find the recovery Health
# implementation.
allow sycamore_health rootfs:dir { read open getattr search };
# Health 2.1 obtains the recovery Health 2.0 passthrough implementation
# through a binder endpoint hosted in the recovery domain.
allow sycamore_health recovery:binder call;
# Health 2.1 must transfer the recovery-hosted passthrough binder object
# while wrapping/registering the inherited Health implementation.
allow sycamore_health recovery:binder transfer;

View file

@ -0,0 +1,6 @@
# TWRP recovery consumes android.hardware.health::IHealth through
# recovery_utils/battery_utils.
#
# Make recovery a Health HAL client only. Do not make recovery a Health
# server domain.
hal_client_domain(recovery, hal_health)

View file

@ -0,0 +1,12 @@
# Recovery stages hwservicemanager on the recovery rootfs, but it must run
# in its native domain so it can own the hwbinder context manager and set
# hwservicemanager.ready.
recovery_only(`
allow hwservicemanager rootfs:file {
entrypoint open read execute getattr map
};
allow hwservicemanager rootfs:dir {
read open
};
')

View file

@ -0,0 +1,7 @@
# The stock KeyMint HAL runs in its native domain, but TWRP's recovery ramdisk
# leaves the dynamic linker and packaged libraries labeled rootfs.
# Permit mapping those immutable ramdisk files; add nothing broader unless
# runtime evidence requires it.
recovery_only(`
allow hal_keymint_default rootfs:file { map read execute getattr open };
')

View file

@ -0,0 +1,13 @@
# Beanpod KeyMint runs in its native hal_keymint_default domain in recovery.
# Mirror the stock XT2575-4 access required for the MediaTek TEE client.
#
# vendor_mtk_soter_teei_prop is intentionally NOT referenced here because
# that stock-only property type is not present in the recovery policy.
recovery_only(`
allow hal_keymint_default teei_client_device:chr_file {
append getattr ioctl lock map open read watch watch_reads write
};
allow hal_keymint_default property_socket:sock_file write;
')

View file

@ -0,0 +1,6 @@
# Keystore2 is staged into the recovery rootfs but runs in its native
# AOSP keystore domain.
recovery_only(`
allow keystore rootfs:file { entrypoint map read execute getattr open };
allow keystore rootfs:dir { read open };
')

7
sepolicy/vendor/sycamore_recovery.te vendored Normal file
View file

@ -0,0 +1,7 @@
# TWRP libpixelflinger/codeflinger creates an executable anonymous code cache.
# Required when the recovery domain is enforcing.
recovery_only(`
allow recovery self:process execmem;
allow recovery ashmem_libcutils_device:chr_file execute;
')

View file

@ -0,0 +1,10 @@
# Recovery hosts crypto components using the classic Binder servicemanager.
# Native Keystore2 runs in u:r:keystore:s0; allow the recovery-side
# fscrypt/vold code to locate and transact with the Keystore2 service.
recovery_only(`
binder_use(recovery)
allow recovery keystore_service:service_manager find;
allow recovery keystore:binder call;
allow keystore recovery:binder transfer;
')

View file

@ -0,0 +1,19 @@
# Recovery performs vold/fscrypt duties while bringing up FBE.
# Permissions are added only as demonstrated necessary by enforcing runtime.
recovery_only(`
# TWRP executes the vold FBE setup in recovery. ro.crypto.type=file triggers
# the device-local init install_keyring action before fscrypt key install.
set_prop(recovery, vold_status_prop)
# installProvisioningKey() searches and inserts fscrypt-provisioning keys
# into the init-created shared fscrypt session keyring.
allow recovery init:key { search setattr write };
allow recovery unencrypted_data_file:dir { getattr search };
allow recovery unencrypted_data_file:file { getattr open read };
# installFsKeyringKey() opens /data before FS_IOC_ADD_ENCRYPTION_KEY.
allow recovery system_data_root_file:dir { read open ioctl };
allowxperm recovery system_data_root_file:dir ioctl 0x6617;
')

View file

@ -0,0 +1,8 @@
# Recovery-only view of the metadata filesystem. The context= mount option
# changes the in-memory mount view without relabeling persistent key files.
type sycamore_recovery_metadata_file, fs_type, contextmount_type;
recovery_only(`
allow recovery sycamore_recovery_metadata_file:dir { getattr search };
allow recovery sycamore_recovery_metadata_file:file { getattr open read };
')

View file

@ -0,0 +1,7 @@
# Recovery performs vold metadata-encryption duties in-process.
# MetadataCrypt.cpp temporarily sets the fsck execution context before
# mounting metadata-encrypted /data.
recovery_only(`
allow recovery self:process setexec;
')

View file

@ -0,0 +1,11 @@
# Recovery performs vold/fscrypt duties during metadata-encrypted /data mount.
# Grant only the stock vold Keystore2 key permissions proven necessary by
# enforcing runtime.
recovery_only(`
allow recovery vold_key:keystore2_key {
convert_storage_key_to_ephemeral
manage_blob
use
};
')

View file

@ -0,0 +1,7 @@
# Recovery ramdisk files retain rootfs labels. Explicit seclabel handles the
# process transition; these are the dynamic ELF entrypoint/read/map permissions
# normally supplied through servicemanager_exec.
recovery_only(`
allow servicemanager rootfs:file { entrypoint open read execute getattr map };
allow servicemanager rootfs:dir { read open };
')

View file

@ -7,6 +7,10 @@ type ut_keymaster_device, dev_type;
type teei_rpmb_device, dev_type;
type utr_tui_device, dev_type;
# V18.1 diagnostic only: keep global recovery enforcing while allowing the
# production tee domain to expose any remaining recovery-rootfs AVC gaps.
permissive tee;
# Permit only the production tee domain to use these device interfaces. The
# daemon receives SYS_RAWIO from init and no other Linux capability.
allow tee self:global_capability_class_set sys_rawio;