Initial TWRP device tree for sycamore_row_5G
This commit is contained in:
parent
6eb2b7516c
commit
11a5d1b7a6
50 changed files with 1777 additions and 144 deletions
2
sepolicy/private/property_contexts
Normal file
2
sepolicy/private/property_contexts
Normal file
|
|
@ -0,0 +1,2 @@
|
|||
# R7v9.60: dynamic twrp.user.<id>.decrypt state
|
||||
twrp.user. u:object_r:twrp_user_decrypt_prop:s0
|
||||
3
sepolicy/public/property.te
Normal file
3
sepolicy/public/property.te
Normal file
|
|
@ -0,0 +1,3 @@
|
|||
|
||||
# R7v9.60: TWRP per-user FBE state shared by vold and recovery.
|
||||
system_public_prop(twrp_user_decrypt_prop)
|
||||
16
sepolicy/vendor/file_contexts
vendored
16
sepolicy/vendor/file_contexts
vendored
|
|
@ -8,3 +8,19 @@
|
|||
/dev/0:0:0:49476 u:object_r:teei_rpmb_device:s0
|
||||
/dev/rpmb0 u:object_r:teei_rpmb_device:s0
|
||||
/dev/utr_tui u:object_r:utr_tui_device:s0
|
||||
|
||||
# Physical misc partition backing /dev/block/by-name/misc.
|
||||
/dev/block/sdc1 u:object_r:misc_block_device:s0
|
||||
|
||||
/dev/dri/card0 u:object_r:graphics_device:s0
|
||||
|
||||
# Physical userdata partition.
|
||||
/dev/block/sdc73 u:object_r:userdata_block_device:s0
|
||||
|
||||
# Stock Beanpod KeyMint HAL copied into the recovery ramdisk.
|
||||
# Label only this executable so it can run in the native KeyMint HAL domain.
|
||||
/vendor/bin/hw/android\.hardware\.security\.keymint@2\.0-service\.beanpod u:object_r:hal_keymint_default_exec:s0
|
||||
|
||||
# Recovery-only crypto helper. Recovery cpio starts as rootfs, so init uses an
|
||||
# explicit native-vold seclabel; this exact mapping documents its intended type.
|
||||
/system/bin/sycamore_fscryptd u:object_r:vold_exec:s0
|
||||
|
|
|
|||
9
sepolicy/vendor/genfs_contexts
vendored
Normal file
9
sepolicy/vendor/genfs_contexts
vendored
Normal file
|
|
@ -0,0 +1,9 @@
|
|||
# Sycamore power-supply sysfs consumed by the recovery Health HAL.
|
||||
#
|
||||
# AOSP Health policy grants hal_health_server access to sysfs_batteryinfo.
|
||||
# Keep these labels device-specific rather than granting generic sysfs access.
|
||||
|
||||
genfscon sysfs /devices/platform/soc/11b20000.i2c/i2c-3/3-0055/power_supply/battery u:object_r:sysfs_batteryinfo:s0
|
||||
genfscon sysfs /devices/platform/soc/11b20000.i2c/i2c-3/3-001a/power_supply/charger u:object_r:sysfs_batteryinfo:s0
|
||||
genfscon sysfs /devices/platform/charger/power_supply/mtk-master-charger u:object_r:sysfs_batteryinfo:s0
|
||||
genfscon sysfs /devices/platform/charger/power_supply/mtk-slave-charger u:object_r:sysfs_batteryinfo:s0
|
||||
35
sepolicy/vendor/sycamore_bootctl.te
vendored
Normal file
35
sepolicy/vendor/sycamore_bootctl.te
vendored
Normal file
|
|
@ -0,0 +1,35 @@
|
|||
# Dedicated recovery BootControl HAL domain. Do not attach the HAL server
|
||||
# attributes to the much broader recovery domain.
|
||||
type sycamore_bootctl, domain;
|
||||
hal_server_domain(sycamore_bootctl, hal_bootctl)
|
||||
|
||||
# Recovery-cpio files all retain rootfs. The service's explicit seclabel selects
|
||||
# this transition; domain_trans supplies init transition plus entrypoint/read/map
|
||||
# access for the executable, linker, implementation, and shared libraries. It
|
||||
# deliberately does not grant execute_no_trans.
|
||||
domain_trans(init, rootfs, sycamore_bootctl)
|
||||
|
||||
# libhardware searches rootfs-backed system/vendor hw directories for the
|
||||
# MTK BootControl implementation. Recovery cpio directories retain rootfs.
|
||||
allow sycamore_bootctl rootfs:dir { read open getattr search };
|
||||
|
||||
# MTK BootControl initialization: observed enforcing AVCs after the
|
||||
# implementation library became reachable.
|
||||
allow sycamore_bootctl proc_cmdline:file { read open getattr };
|
||||
allow sycamore_bootctl sysfs_dt_firmware_android:dir search;
|
||||
allow sycamore_bootctl block_device:dir search;
|
||||
allow sycamore_bootctl metadata_file:dir search;
|
||||
allow sycamore_bootctl sycamore_recovery_metadata_file:dir search;
|
||||
|
||||
# MTK BootControl reads the Android DT compatible node during initialization.
|
||||
allow sycamore_bootctl sysfs_dt_firmware_android:file { read open getattr };
|
||||
|
||||
# fs_mgr's recovery fstab reader probes the DSU/GSI boot indicator.
|
||||
# Directory search is required so a nonexistent indicator returns ENOENT
|
||||
# rather than EACCES, which ReadFstabFromFile treats as fatal.
|
||||
allow sycamore_bootctl gsi_metadata_file:dir search;
|
||||
|
||||
# BootControl reads/writes the A/B bootloader control and Virtual A/B
|
||||
# metadata stored in the misc partition. The physical device is labeled
|
||||
# misc_block_device by the device-specific file_contexts rule.
|
||||
allow sycamore_bootctl misc_block_device:blk_file rw_file_perms;
|
||||
85
sepolicy/vendor/sycamore_fscryptd.te
vendored
Normal file
85
sepolicy/vendor/sycamore_fscryptd.te
vendored
Normal file
|
|
@ -0,0 +1,85 @@
|
|||
# sycamore_fscryptd is staged in recovery cpio but deliberately runs in vold's
|
||||
# native domain. Grant only immutable rootfs entrypoint/runtime access and the
|
||||
# private recovery-to-vold Unix-socket connection.
|
||||
recovery_only(`
|
||||
allow vold rootfs:file { entrypoint execute getattr open read map };
|
||||
allow vold rootfs:dir { getattr search open read };
|
||||
# fs_mgr ReadDefaultFstab probes recovery-mounted metadata/DSU state.
|
||||
# /metadata is forced to sycamore_recovery_metadata_file in recovery.
|
||||
allow vold sycamore_recovery_metadata_file:dir search;
|
||||
|
||||
# TWRP KeyStorage stages an upgraded KeyMint blob under /tmp/keymaster_key_blob.
|
||||
# The file is created earlier by recovery metadata decrypt; native vold only
|
||||
# needs the demonstrated write permission when systemwide fscrypt reuses it.
|
||||
allow vold tmpfs:file { open write };
|
||||
|
||||
allow recovery vold:unix_stream_socket connectto;
|
||||
')
|
||||
|
||||
# R7v9.41: recovery-cpio linker64 remains rootfs; permit only ELF mapping
|
||||
allow vold_prepare_subdirs rootfs:file { execute getattr map open read };
|
||||
|
||||
allow hal_gatekeeper_default rootfs:file { execute getattr map open read };
|
||||
allow vold_prepare_subdirs rootfs:dir read;
|
||||
|
||||
# R7v9.51: complete stock-style read-side SQLite access to locksettings.db
|
||||
allow recovery system_data_file:file { getattr ioctl lock open read };
|
||||
|
||||
# R7v9.58: Gatekeeper recovery-rootfs HAL/library directory enumeration
|
||||
allow hal_gatekeeper_default rootfs:dir { open read };
|
||||
|
||||
# R7v9.60: TWRP per-user FBE state published by vold and consumed by recovery.
|
||||
# Without this property, Parse_Users() skips locked user 0 entirely.
|
||||
|
||||
set_prop(vold, twrp_user_decrypt_prop)
|
||||
get_prop(recovery, twrp_user_decrypt_prop)
|
||||
set_prop(recovery, twrp_user_decrypt_prop)
|
||||
|
||||
|
||||
# R7v9.61: recovery is a client of the already-running Gatekeeper HAL
|
||||
# for synthetic-password credential verification.
|
||||
hal_client_domain(recovery, hal_gatekeeper)
|
||||
|
||||
# R7v9.62: Beanpod Gatekeeper credential verification talks to
|
||||
# /dev/isee_tee0, labeled teei_client_device in recovery.
|
||||
allow hal_gatekeeper_default teei_client_device:chr_file { ioctl map open read write };
|
||||
|
||||
# R7v9.66: recovery submits the Gatekeeper HardwareAuthToken to
|
||||
# Keystore2's android.security.authorization AIDL service.
|
||||
allow recovery authorization_service:service_manager find;
|
||||
|
||||
# R7v9.69: Keystore2 operates SQLite's recovery-side persistent database
|
||||
# plus its journal/WAL/SHM sidecars under /tmp/misc/keystore.
|
||||
#
|
||||
# This is one logical SQLite lifecycle permission set rather than one
|
||||
# permission-per-flash debugging.
|
||||
allow keystore tmpfs:dir {
|
||||
add_name
|
||||
getattr
|
||||
open
|
||||
read
|
||||
remove_name
|
||||
search
|
||||
write
|
||||
};
|
||||
|
||||
allow keystore tmpfs:file {
|
||||
create
|
||||
getattr
|
||||
ioctl
|
||||
lock
|
||||
map
|
||||
open
|
||||
read
|
||||
setattr
|
||||
unlink
|
||||
write
|
||||
};
|
||||
|
||||
# R7v9.70: Android SQLite probes the backing filesystem with ioctl 0xf50c.
|
||||
# Ordinary ioctl permission does not authorize command-specific xperms.
|
||||
allowxperm keystore tmpfs:file ioctl 0xf50c;
|
||||
|
||||
# R7v9.69: recovery submits the Gatekeeper-generated HardwareAuthToken
|
||||
# through android.security.authorization to Keystore2.
|
||||
allow recovery keystore:keystore2 add_auth;
|
||||
23
sepolicy/vendor/sycamore_health.te
vendored
Normal file
23
sepolicy/vendor/sycamore_health.te
vendored
Normal file
|
|
@ -0,0 +1,23 @@
|
|||
# Dedicated recovery Health HAL domain. Do not attach hal_health_server
|
||||
# to the broad recovery domain.
|
||||
type sycamore_health, domain;
|
||||
|
||||
hal_server_domain(sycamore_health, hal_health)
|
||||
|
||||
# Recovery-cpio executables retain the rootfs label. The service's explicit
|
||||
# seclabel selects this domain; domain_trans supplies init transition and
|
||||
# executable entrypoint access.
|
||||
domain_trans(init, rootfs, sycamore_health)
|
||||
|
||||
# Recovery cpio directories retain rootfs. Health's passthrough loader must
|
||||
# traverse /system and its hw-library paths to find the recovery Health
|
||||
# implementation.
|
||||
allow sycamore_health rootfs:dir { read open getattr search };
|
||||
|
||||
# Health 2.1 obtains the recovery Health 2.0 passthrough implementation
|
||||
# through a binder endpoint hosted in the recovery domain.
|
||||
allow sycamore_health recovery:binder call;
|
||||
|
||||
# Health 2.1 must transfer the recovery-hosted passthrough binder object
|
||||
# while wrapping/registering the inherited Health implementation.
|
||||
allow sycamore_health recovery:binder transfer;
|
||||
6
sepolicy/vendor/sycamore_health_client.te
vendored
Normal file
6
sepolicy/vendor/sycamore_health_client.te
vendored
Normal file
|
|
@ -0,0 +1,6 @@
|
|||
# TWRP recovery consumes android.hardware.health::IHealth through
|
||||
# recovery_utils/battery_utils.
|
||||
#
|
||||
# Make recovery a Health HAL client only. Do not make recovery a Health
|
||||
# server domain.
|
||||
hal_client_domain(recovery, hal_health)
|
||||
12
sepolicy/vendor/sycamore_hwservicemanager_recovery.te
vendored
Normal file
12
sepolicy/vendor/sycamore_hwservicemanager_recovery.te
vendored
Normal file
|
|
@ -0,0 +1,12 @@
|
|||
# Recovery stages hwservicemanager on the recovery rootfs, but it must run
|
||||
# in its native domain so it can own the hwbinder context manager and set
|
||||
# hwservicemanager.ready.
|
||||
|
||||
recovery_only(`
|
||||
allow hwservicemanager rootfs:file {
|
||||
entrypoint open read execute getattr map
|
||||
};
|
||||
allow hwservicemanager rootfs:dir {
|
||||
read open
|
||||
};
|
||||
')
|
||||
7
sepolicy/vendor/sycamore_keymint_recovery.te
vendored
Normal file
7
sepolicy/vendor/sycamore_keymint_recovery.te
vendored
Normal file
|
|
@ -0,0 +1,7 @@
|
|||
# The stock KeyMint HAL runs in its native domain, but TWRP's recovery ramdisk
|
||||
# leaves the dynamic linker and packaged libraries labeled rootfs.
|
||||
# Permit mapping those immutable ramdisk files; add nothing broader unless
|
||||
# runtime evidence requires it.
|
||||
recovery_only(`
|
||||
allow hal_keymint_default rootfs:file { map read execute getattr open };
|
||||
')
|
||||
13
sepolicy/vendor/sycamore_keymint_tee_recovery.te
vendored
Normal file
13
sepolicy/vendor/sycamore_keymint_tee_recovery.te
vendored
Normal file
|
|
@ -0,0 +1,13 @@
|
|||
# Beanpod KeyMint runs in its native hal_keymint_default domain in recovery.
|
||||
# Mirror the stock XT2575-4 access required for the MediaTek TEE client.
|
||||
#
|
||||
# vendor_mtk_soter_teei_prop is intentionally NOT referenced here because
|
||||
# that stock-only property type is not present in the recovery policy.
|
||||
|
||||
recovery_only(`
|
||||
allow hal_keymint_default teei_client_device:chr_file {
|
||||
append getattr ioctl lock map open read watch watch_reads write
|
||||
};
|
||||
|
||||
allow hal_keymint_default property_socket:sock_file write;
|
||||
')
|
||||
6
sepolicy/vendor/sycamore_keystore_recovery.te
vendored
Normal file
6
sepolicy/vendor/sycamore_keystore_recovery.te
vendored
Normal file
|
|
@ -0,0 +1,6 @@
|
|||
# Keystore2 is staged into the recovery rootfs but runs in its native
|
||||
# AOSP keystore domain.
|
||||
recovery_only(`
|
||||
allow keystore rootfs:file { entrypoint map read execute getattr open };
|
||||
allow keystore rootfs:dir { read open };
|
||||
')
|
||||
7
sepolicy/vendor/sycamore_recovery.te
vendored
Normal file
7
sepolicy/vendor/sycamore_recovery.te
vendored
Normal file
|
|
@ -0,0 +1,7 @@
|
|||
|
||||
# TWRP libpixelflinger/codeflinger creates an executable anonymous code cache.
|
||||
# Required when the recovery domain is enforcing.
|
||||
recovery_only(`
|
||||
allow recovery self:process execmem;
|
||||
allow recovery ashmem_libcutils_device:chr_file execute;
|
||||
')
|
||||
10
sepolicy/vendor/sycamore_recovery_binder_client.te
vendored
Normal file
10
sepolicy/vendor/sycamore_recovery_binder_client.te
vendored
Normal file
|
|
@ -0,0 +1,10 @@
|
|||
# Recovery hosts crypto components using the classic Binder servicemanager.
|
||||
# Native Keystore2 runs in u:r:keystore:s0; allow the recovery-side
|
||||
# fscrypt/vold code to locate and transact with the Keystore2 service.
|
||||
|
||||
recovery_only(`
|
||||
binder_use(recovery)
|
||||
allow recovery keystore_service:service_manager find;
|
||||
allow recovery keystore:binder call;
|
||||
allow keystore recovery:binder transfer;
|
||||
')
|
||||
19
sepolicy/vendor/sycamore_recovery_fscrypt.te
vendored
Normal file
19
sepolicy/vendor/sycamore_recovery_fscrypt.te
vendored
Normal file
|
|
@ -0,0 +1,19 @@
|
|||
# Recovery performs vold/fscrypt duties while bringing up FBE.
|
||||
# Permissions are added only as demonstrated necessary by enforcing runtime.
|
||||
|
||||
recovery_only(`
|
||||
# TWRP executes the vold FBE setup in recovery. ro.crypto.type=file triggers
|
||||
# the device-local init install_keyring action before fscrypt key install.
|
||||
set_prop(recovery, vold_status_prop)
|
||||
|
||||
# installProvisioningKey() searches and inserts fscrypt-provisioning keys
|
||||
# into the init-created shared fscrypt session keyring.
|
||||
allow recovery init:key { search setattr write };
|
||||
|
||||
allow recovery unencrypted_data_file:dir { getattr search };
|
||||
allow recovery unencrypted_data_file:file { getattr open read };
|
||||
|
||||
# installFsKeyringKey() opens /data before FS_IOC_ADD_ENCRYPTION_KEY.
|
||||
allow recovery system_data_root_file:dir { read open ioctl };
|
||||
allowxperm recovery system_data_root_file:dir ioctl 0x6617;
|
||||
')
|
||||
8
sepolicy/vendor/sycamore_recovery_metadata.te
vendored
Normal file
8
sepolicy/vendor/sycamore_recovery_metadata.te
vendored
Normal file
|
|
@ -0,0 +1,8 @@
|
|||
# Recovery-only view of the metadata filesystem. The context= mount option
|
||||
# changes the in-memory mount view without relabeling persistent key files.
|
||||
type sycamore_recovery_metadata_file, fs_type, contextmount_type;
|
||||
|
||||
recovery_only(`
|
||||
allow recovery sycamore_recovery_metadata_file:dir { getattr search };
|
||||
allow recovery sycamore_recovery_metadata_file:file { getattr open read };
|
||||
')
|
||||
7
sepolicy/vendor/sycamore_recovery_metadata_mount.te
vendored
Normal file
7
sepolicy/vendor/sycamore_recovery_metadata_mount.te
vendored
Normal file
|
|
@ -0,0 +1,7 @@
|
|||
# Recovery performs vold metadata-encryption duties in-process.
|
||||
# MetadataCrypt.cpp temporarily sets the fsck execution context before
|
||||
# mounting metadata-encrypted /data.
|
||||
|
||||
recovery_only(`
|
||||
allow recovery self:process setexec;
|
||||
')
|
||||
11
sepolicy/vendor/sycamore_recovery_vold_key.te
vendored
Normal file
11
sepolicy/vendor/sycamore_recovery_vold_key.te
vendored
Normal file
|
|
@ -0,0 +1,11 @@
|
|||
# Recovery performs vold/fscrypt duties during metadata-encrypted /data mount.
|
||||
# Grant only the stock vold Keystore2 key permissions proven necessary by
|
||||
# enforcing runtime.
|
||||
|
||||
recovery_only(`
|
||||
allow recovery vold_key:keystore2_key {
|
||||
convert_storage_key_to_ephemeral
|
||||
manage_blob
|
||||
use
|
||||
};
|
||||
')
|
||||
7
sepolicy/vendor/sycamore_servicemanager.te
vendored
Normal file
7
sepolicy/vendor/sycamore_servicemanager.te
vendored
Normal file
|
|
@ -0,0 +1,7 @@
|
|||
# Recovery ramdisk files retain rootfs labels. Explicit seclabel handles the
|
||||
# process transition; these are the dynamic ELF entrypoint/read/map permissions
|
||||
# normally supplied through servicemanager_exec.
|
||||
recovery_only(`
|
||||
allow servicemanager rootfs:file { entrypoint open read execute getattr map };
|
||||
allow servicemanager rootfs:dir { read open };
|
||||
')
|
||||
4
sepolicy/vendor/teei_device.te
vendored
4
sepolicy/vendor/teei_device.te
vendored
|
|
@ -7,6 +7,10 @@ type ut_keymaster_device, dev_type;
|
|||
type teei_rpmb_device, dev_type;
|
||||
type utr_tui_device, dev_type;
|
||||
|
||||
# V18.1 diagnostic only: keep global recovery enforcing while allowing the
|
||||
# production tee domain to expose any remaining recovery-rootfs AVC gaps.
|
||||
permissive tee;
|
||||
|
||||
# Permit only the production tee domain to use these device interfaces. The
|
||||
# daemon receives SYS_RAWIO from init and no other Linux capability.
|
||||
allow tee self:global_capability_class_set sys_rawio;
|
||||
|
|
|
|||
Loading…
Reference in a new issue