Prd/components/sepolicy-patch/README.md
Lucy Doupalů be9f14ce34 Helpdesk - operator console + patched GrapheneOS Dialer for call handling
A small helpdesk system: an office Pixel running a patched GrapheneOS Dialer
answers technician calls, records both call legs as separate channels, and a
Ruby backend transcribes them through Whisper and files an AI summary against
the caller.

Squashed to a single commit for sharing. No credentials are included; secrets
live outside the repo in /etc/helpdesk/env on the server or a gitignored
.claude/env.local locally. See .claude/env.local.example for the shape.

Start at README.md, then docs/architecture.md.
2026-07-27 18:50:32 +02:00

807 B

Helpdesk sepolicy patch (GrapheneOS system/sepolicy)

Declares a private helpdesk_prop property type so the patched Dialer (priv_app) can READ its backend config (ro.helpdesk.* / persist.helpdesk.*) and shell can SET it (live re-pointing on dev builds). Without this, custom *.helpdesk.* props get default_prop context which priv_app cannot read, so the persist/ro pin never applies (confirmed on-device 2026-07-09: avc + priv_app_36 can't read default_prop).

Apply into the tree before building: bash components/sepolicy-patch/apply.sh (applies patches/0001-helpdesk-prop.patch to /build/grapheneos/system/sepolicy). Validate with m selinux_policy (runs the neverallow/treble/freeze checks). Declared PRIVATE (private/property.te) so it doesn't trip the public-policy freeze/treble tests.