Commit Graph

997 Commits

Author SHA1 Message Date
Android Build Coastguard Worker
dcafe61f09 Snap for 10313683 from d19ec7a5b6 to udc-qpr1-release
Change-Id: Ic945902e7bec0af3830c0eabe6080b37912fb7c0
2023-06-14 02:28:07 +00:00
Joerg Wagner
d19ec7a5b6 Merge "Prepare for Mali r44p0 UMD update" into udc-qpr-dev 2023-06-13 06:03:15 +00:00
Android Build Coastguard Worker
655617578b Snap for 10309372 from cac09c20ba to udc-qpr1-release
Change-Id: I584e3962d263699bae3223658b05bd64c0f8629e
2023-06-13 03:02:48 +00:00
Ruofei Ma
cac09c20ba Merge "mediacodec_google: add hal_power" into udc-d1-dev am: abd1dee381
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23618633

Change-Id: Ib439b6d6464dcdaab8337ada3558780579363843
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-12 15:53:18 +00:00
Ruofei Ma
abd1dee381 Merge "mediacodec_google: add hal_power" into udc-d1-dev 2023-06-12 15:17:42 +00:00
TreeHugger Robot
00ed1044ff Merge changes from topic "283841311" into udc-d1-dev am: 032d9942de
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23629344

Change-Id: Id39de7c6a03f11dd3d74e3ce9f9a0deca58873a3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-12 07:18:17 +00:00
TreeHugger Robot
032d9942de Merge changes from topic "283841311" into udc-d1-dev
* changes:
  Allow systemui_app access statsmanager_service
  Move systemui_app to system_ext
2023-06-12 06:30:36 +00:00
Wilson Sung
5ac528406e Allow systemui_app access statsmanager_service
Bug: 283841311
Change-Id: Id3c2838179736b42070959b3dad7c2ecd5580f22
2023-06-12 10:26:46 +08:00
Wilson Sung
7b19701919 Move systemui_app to system_ext
Bug: 283841311
Bug: 264266705
Change-Id: I6c2f167cda9a52da4698f3732c9fdbb13674bea8
2023-06-12 10:26:31 +08:00
Krzysztof Kosiński
9332337e8e Remove Google Camera access to GXP firmware. am: 35910a3e8b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23612126

Change-Id: I5efdb04c8be5e6d3a01850ff747ca5c7b20992f8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-12 02:03:17 +00:00
Android Build Coastguard Worker
651940e9a0 Snap for 10289553 from 088b6c2879 to udc-qpr1-release
Change-Id: Ia3cfe45a4073b75977412dc27a71aed6cbed727c
2023-06-09 03:02:35 +00:00
Ruofei Ma
3346e879e6 mediacodec_google: add hal_power
Add mediacodec_google as a client to hal_power for it to
do power hint.

Bug: 274736629

Change-Id: Ib07001be6ae4aaeaebf2e97439b9af0766640dc9
Signed-off-by: Ruofei Ma <ruofeim@google.com>
2023-06-08 18:28:50 +00:00
Krzysztof Kosiński
35910a3e8b Remove Google Camera access to GXP firmware.
This was originally a workaround and is not needed on Zuma.

Bug: 264489778
Test: gca_smoke.py on zuma device
Change-Id: I35d168a2f832a430ec1b782b12fb642bcea4bfd1
2023-06-08 10:19:18 +00:00
Treehugger Robot
088b6c2879 Merge "Add sepolicies for gcma_camera heaps" into udc-d1-dev am: 8733772e74
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22298464

Change-Id: I0ee764a32b7d46acd14160228f32fe81b2708990
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-08 07:22:34 +00:00
Treehugger Robot
8733772e74 Merge "Add sepolicies for gcma_camera heaps" into udc-d1-dev 2023-06-08 06:25:44 +00:00
Android Build Coastguard Worker
65c0c041c7 Snap for 10277391 from 4c051c0cc2 to udc-qpr1-release
Change-Id: I80861d8015eece79e7d81953e195b9149116817e
2023-06-08 01:03:17 +00:00
Jörg Wagner
ce42de2ebd Prepare for Mali r44p0 UMD update
Add selinux rule to allow new V2 interface file alongside of V1 used up to r43p0.
The V1 entry will be removed once the r44p0 UMD update completes.
This decouples small changes from large, potentially intrusive ones in
other repositories.

Bug: 284254900
Change-Id: Ia928f871d8ea1fdbfb963cecb8fc4a99947e443e
2023-06-07 10:19:17 +00:00
Android Build Coastguard Worker
ae1bfc5a03 Snap for 10268796 from 77bbb28eae to udc-qpr1-release
Change-Id: I4f716224f4666e9a606c148ded523adcf3edbde6
2023-06-07 03:03:06 +00:00
Wei Wang
4c051c0cc2 Merge "SELinux: allow to access GPU dvfs period change" into udc-d1-dev am: 55020988a0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/22480582

Change-Id: I2d294b36b2ce9a6eaf47963bc2387b083e1c2050
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-06 22:55:16 +00:00
Wei Wang
55020988a0 Merge "SELinux: allow to access GPU dvfs period change" into udc-d1-dev 2023-06-06 22:25:11 +00:00
Zixuan Lan
77bbb28eae Merge "remove 280706211 from bug map" into udc-d1-dev am: bdee55bb57
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23575516

Change-Id: Ie3c0aed656b9a9be90fca81894b989ce0fb226bd
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-06 13:40:43 +00:00
Zixuan Lan
bdee55bb57 Merge "remove 280706211 from bug map" into udc-d1-dev 2023-06-06 13:02:17 +00:00
Allen Xu
4a13ad4cc2 Add sepolicy for ConnectivityMonitor am: 78b62802e4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23575448

Change-Id: Ie7c9013431ba535001797e30b984a1f57340ed08
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-06 06:37:54 +00:00
Allen Xu
78b62802e4 Add sepolicy for ConnectivityMonitor
Bug: 264489520
Test: v2/pixel-pts/base
Change-Id: I669a538fe3d0a03422638d7d19fc62a793246f6b
2023-06-06 02:01:38 +00:00
Zixuan Lan
76b53940a9 remove 280706211 from bug map
Bug: 280706211
Test: adb log
Change-Id: I167041363a27c294a3c8d2d2fb145ce751a34db7
2023-06-06 08:30:25 +08:00
Android Build Coastguard Worker
d3cf064eb6 Snap for 10245577 from 5ab934799d to udc-qpr1-release
Change-Id: I362c965515b429b07a33b67ce6be6944a021736f
2023-06-02 03:02:25 +00:00
Leo Hsieh
5ab934799d Merge "Allow hal_fingerprint_default to access sysfs_aoc_udfps [DO NOT MERGE]" into udc-d1-dev am: 72577756e2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23482807

Change-Id: Ie15f3a943605194780e76b2f6c5c76263fc6f519
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-01 13:29:03 +00:00
leohsieh
f225931a7c Allow hal_fingerprint_default to access sysfs_aoc_udfps [DO NOT MERGE] am: 458b60e5c9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23482807

Change-Id: If23a454731b5ce0045a27923066c42526322ce9d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-01 13:29:02 +00:00
Leo Hsieh
72577756e2 Merge "Allow hal_fingerprint_default to access sysfs_aoc_udfps [DO NOT MERGE]" into udc-d1-dev 2023-06-01 12:40:24 +00:00
Mark su
73334bf1d1 Add video12 as hw_jpg_device and enable it for debug_camera_app am: 51c91e5bdf
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23053881

Change-Id: I27031f93a5210145bcb50acbf8f4707c9459b113
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-01 07:34:54 +00:00
Android Build Coastguard Worker
f6dc1820c1 Snap for 10233403 from 3f157f2b26 to udc-qpr1-release
Change-Id: I9321de05a665c59f1a60172129bb2b51befd868e
2023-06-01 02:37:28 +00:00
TreeHugger Robot
3f157f2b26 Merge "Remove old secure_element HIDL permission" into udc-d1-dev am: 23440aa9df
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23466920

Change-Id: I52c70ff896514058585b1d5ef6810331005758cd
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-31 06:25:04 +00:00
Mark su
51c91e5bdf Add video12 as hw_jpg_device and enable it for debug_camera_app
Test: 05-05 05:07:06.652  4616  4616 W FinishThread: type=1400 audit(0.0:24): avc:  denied  { read write } for  name="video12" dev="tmpfs" ino=646 scontext=u:r:debug_camera_app:s0:c32,c257,c512,c768 tcontext=u:object_r:video_device:s0 tclass=chr_file permissive=0 app=com.google.android.GoogleCameraEng
05-08 22:00:59.000  7323  7323 I FinishThread: type=1400 audit(0.0:36): avc:  denied  { read } for  name="lib_jpg_encoder.so"
 dev="dm-45" ino=25639 scontext=u:r:debug_camera_app:s0:c32,c257,c512,c768 tcontext=u:object_r:vendor_camera_data_file:s0 tcl
ass=file permissive=1 app=com.google.android.GoogleCameraEng

05-08 22:00:59.000  7323  7323 I FinishThread: type=1400 audit(0.0:37): avc:  denied  { open } for  path="/vendor/lib64/lib_j
pg_encoder.so" dev="dm-45" ino=25639 scontext=u:r:debug_camera_app:s0:c32,c257,c512,c768 tcontext=u:object_r:vendor_camera_da
ta_file:s0 tclass=file permissive=1 app=com.google.android.GoogleCameraEng

05-08 22:46:00.260  4784  4784 I FinishThread: type=1400 audit(0.0:29): avc:  denied  { execute } for  path="/vendor/lib64/
libhwjpeg.so" dev="dm-50" ino=55596 scontext=u:r:debug_camera_app:s0:c32,c257,c512,c768 tcontext=u:object_r:vendor_camera_d
ata_file:s0 tclass=file permissive=1 app=com.google.android.GoogleCameraEng

05-08 22:33:30.504  7436  7436 I FinishThread: type=1400 audit(0.0:36): avc:  denied  { getattr } for  path="/vendor/lib64/
lib_jpg_encoder.so" dev="dm-50" ino=53765 scontext=u:r:debug_camera_app:s0:c32,c257,c512,c768 tcontext=u:object_r:vendor_ca
mera_data_file:s0 tclass=file permissive=1 app=com.google.android.GoogleCameraEng

05-08 22:33:30.504  7436  7436 I FinishThread: type=1400 audit(0.0:37): avc:  denied  { map } for  path="/vendor/lib64/lib_
jpg_encoder.so" dev="dm-50" ino=53765 scontext=u:r:debug_camera_app:s0:c32,c257,c512,c768 tcontext=u:object_r:vendor_camera
_data_file:s0 tclass=file permissive=1 app=com.google.android.GoogleCameraEng

binder:7312_2: type=1400 audit(0.0:18): avc:  denied  { read write } for  name="video12" dev="tmpfs" ino=680 scontext=u:r:hal_camera_default:s0 tcontext=u:object_r:hw_jpg_device:s0 tclass=chr_file permissive=1
05-08 22:28:37.692  7312  7312 I binder:7312_2: type=1400 audit(0.0:19): avc:  denied  { open } for  path="/dev/video12" dev="tmpfs" ino=680 scontext=u:r:hal_camera_default:s0 tcontext=u:object_r:hw_jpg_device:s0 tclass=chr_file permissive=1

05-08 22:28:37.692  7312  7312 I binder:7312_2: type=1400 audit(0.0:20): avc:  denied  { ioctl } for  path="/dev/video12" dev="tmpfs" ino=680 ioctlcmd=0x5600 scontext=u:r:hal_camera_default:s0 tcontext=u:object_r:hw_jpg_device:s0 tclass=chr_file permissive=1

05-08 22:28:37.700  7312  7312 I binder:7312_2: type=1400 audit(0.0:21): avc:  denied  { read } for  name="u:object_r:default_prop:s0" dev="tmpfs" ino=167 scontext=u:r:hal_camera_default:s0 tcontext=u:object_r:default_prop:s0 tclass=file permissive=1

Bug: 267820687
Change-Id: I69f502d721f683d3532038d618f5fafc83f38b6b
2023-05-31 06:08:46 +00:00
TreeHugger Robot
23440aa9df Merge "Remove old secure_element HIDL permission" into udc-d1-dev 2023-05-31 05:27:32 +00:00
leohsieh
458b60e5c9 Allow hal_fingerprint_default to access sysfs_aoc_udfps [DO NOT MERGE]
Fix the following avc denial:
avc: denied { search } for name="17000000.aoc" dev="sysfs" ino=22035 scontext=u:r:hal_fingerprint_default:s0 tcontext=u:object_r:sysfs_aoc:s0 tclass=dir permissive=0
avc: denied { write } for name="udfps_set_clock_source" dev="sysfs" ino=106891 scontext=u:r:hal_fingerprint_default:s0 tcontext=u:object_r:sysfs_aoc_udfps:s0 tclass=file permissive=0
avc: denied { read } for name="udfps_get_disp_freq" dev="sysfs" ino=106893 scontext=u:r:hal_fingerprint_default:s0 tcontext=u:object_r:sysfs_aoc_udfps:s0 tclass=file permissive=0

Bug: 267271482
Test: Verify fingerprint HAL process can read/write to the sysfs node.
Change-Id: I39a2e69b1c314d52944bb16ada61e7e6761561cf
2023-05-31 13:16:43 +08:00
Dinesh Yadav
d3f5a8b038 Merge "Add SEPolicy for gxp_metrics_logger.so logging to stats service" into udc-d1-dev am: 15f5afcfab
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23265297

Change-Id: If50c2234c819bba039e421782381e5835c71ba02
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-31 03:20:24 +00:00
Hyungjun Park
6de0a33f0a Remove old secure_element HIDL permission
AIDL HAL is used in the new project and remove the old HIDL part.

Bug: 280530945
Test: VTS pass

Change-Id: Idd38fc59d7e89e2cafab5f4693d00abd6d4fb138
Signed-off-by: Hyungjun Park <hjun78.park@samsung.com>
2023-05-31 03:12:02 +00:00
Dinesh Yadav
15f5afcfab Merge "Add SEPolicy for gxp_metrics_logger.so logging to stats service" into udc-d1-dev 2023-05-31 02:22:42 +00:00
Android Build Coastguard Worker
002a8c97dc Snap for 10220938 from cb1221098a to udc-qpr1-release
Change-Id: I2302d863309b713ebf86f1ff14d53bba2a46dfa6
2023-05-30 01:07:44 +00:00
Chung-Kai (Michael) Mei
cb1221098a Merge "sepolicy: ignore avc denial" into udc-d1-dev am: ca068bf60b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23445936

Change-Id: Ie14b266747f7737678665d9d86d206a0ef2a5e37
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-29 06:24:10 +00:00
Chung-Kai (Michael) Mei
ca068bf60b Merge "sepolicy: ignore avc denial" into udc-d1-dev 2023-05-29 05:47:43 +00:00
Chungkai Mei
e97101a6e8 sepolicy: ignore avc denial
ignore avc denial since it's debugfs

Bug: 271931921
Test: device-boot-health-check-extra test show passed https://android-build.googleplex.com/builds/abtd/run/L74000000960917226
Change-Id: I5f491f02c99776251cf3893de6224fb0f02cb320
Signed-off-by: Chungkai Mei <chungkai@google.com>
2023-05-29 03:11:41 +00:00
Android Build Coastguard Worker
f57e5e357e Snap for 10213992 from 363d20bf36 to udc-qpr1-release
Change-Id: I44500806456d9eb182183c0f490f6f3f1470575c
2023-05-27 05:08:57 +00:00
Donnie Pollitz
363d20bf36 Merge "Allow vendor_init to fix permissions of TEE data file" into udc-d1-dev am: 9fc92bdb28
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23413076

Change-Id: Ic6dfeafbab9bd207716fc701137ce66746f4b1eb
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-26 07:54:11 +00:00
Donnie Pollitz
9fc92bdb28 Merge "Allow vendor_init to fix permissions of TEE data file" into udc-d1-dev 2023-05-26 07:17:41 +00:00
Dinesh Yadav
e6d2f01a89 Add SEPolicy for gxp_metrics_logger.so logging to stats service
In order to access the gxp metrics library from the google camera
app (product partition), we need to create an SELinux exception for
the related shared library (in vendor) it uses.
This CL adds the same_process_hal_file tag to allow this exception.

Bug: 278516358
Change-Id: I42d41243d3ee47ebff4f766cd769b5387fd20852
2023-05-26 04:01:09 +00:00
Android Build Coastguard Worker
19eb1c4762 Snap for 10204122 from af8727c24e to udc-qpr1-release
Change-Id: I82084a8443ada17b3f12d6959787b9e40658efb2
2023-05-26 01:09:01 +00:00
TreeHugger Robot
af8727c24e Merge "thermal: thermal_metrics: Update selinux to reset stats" into udc-d1-dev am: df113325a5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/zuma-sepolicy/+/23078038

Change-Id: I6995431b91f4dd93a1311155df686d2ba39f111c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-25 06:22:31 +00:00
TreeHugger Robot
df113325a5 Merge "thermal: thermal_metrics: Update selinux to reset stats" into udc-d1-dev 2023-05-25 05:28:46 +00:00
Android Build Coastguard Worker
464fc09491 Snap for 10196038 from 72f862ed29 to udc-qpr1-release
Change-Id: Ia1f7963ac52834f16828a6d5d469aaabe523a65e
2023-05-25 02:42:40 +00:00