Commit graph

157 commits

Author SHA1 Message Date
Ken Yang
9b6820b26f SELinux: fix wakeup selinux issue
Bug: 305600876
Change-Id: I4be4254eb511b283a48bd6d561745e920e568ef0
Signed-off-by: Ken Yang <yangken@google.com>
2023-10-20 05:45:16 +00:00
Alan Chen
7f7c1cabeb [automerger skipped] Allow gril to use radio ext aidl am: c723e3e5a2 am: a06f6aec98 -s ours
am skip reason: Merged-In If72630b90eb1f15a832a936cd080604a486cd17f with SHA-1 32e2b620d1 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/25109723

Change-Id: Ide00a776de463cbecd670292b88c10d60aa3bd55
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-10-20 05:21:21 +00:00
Alan Chen
a06f6aec98 Allow gril to use radio ext aidl am: c723e3e5a2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/25109723

Change-Id: I9a9b218342e459cadd1880f038506627c93a5e7f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-10-20 04:19:29 +00:00
Alan Chen
c723e3e5a2 Allow gril to use radio ext aidl
These changes are copied from the reverted commit
2d635d58d3 (ag/24847488).

Bug: 285459428
Test: manual - verified there are no avc denied logs
Change-Id: If72630b90eb1f15a832a936cd080604a486cd17f
Merged-In: If72630b90eb1f15a832a936cd080604a486cd17f
2023-10-19 08:32:58 +00:00
Alan Chen
32e2b620d1 Allow gril to use radio ext aidl
These changes are copied from the reverted commit
2d635d58d3 (ag/24847488).

Bug: 285459428
Test: manual - verified there are no avc denied logs
Change-Id: If72630b90eb1f15a832a936cd080604a486cd17f
2023-10-18 03:57:06 +00:00
Shinru Han
f36237cfee gps: Allow vendor_init set gps property am: aeb740e7c4 am: 1cd4799530
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/25068816

Change-Id: I126208700ff0dc1e7e9b6e053bdae433c0db9ee8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-10-18 03:36:34 +00:00
Shinru Han
1cd4799530 gps: Allow vendor_init set gps property am: aeb740e7c4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/25068816

Change-Id: I4cf8d9527eaa49386233240965ef886da5c8abab
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-10-18 02:51:55 +00:00
Shinru Han
aeb740e7c4 gps: Allow vendor_init set gps property
W /system/bin/init: type=1107 audit(0.0:4): uid=0 auid=4294967295 ses=4294967295 subj=u:r:init:s0 msg='avc:  denied  { set } for property=persist.vendor.gps.hal.service.name pid=1 uid=0 gid=0 scontext=u:r:vendor_init:s0 tcontext=u:object_r:vendor_gps_prop:s0 tclass=property_service permissive=0'

Test: gps property is present on user build
Test: atest VtsHalGnssTargetTest on user build
Bug: 305162098
Change-Id: Ic56413182d0d721a1543b3b510e17f39813c7ad3
2023-10-17 08:12:48 +00:00
Wilson Sung
8664ef6d50 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 305600460
Bug: 305600876
Change-Id: I110045274188a16264a90317d208c8b895addcb0
2023-10-16 05:59:40 +00:00
Cheng Chang
f4886a36cc gps: add sepolicy to coredump node am: 1ee114f4d7 am: d42a620d41
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/24918561

Change-Id: I3f6440accd1b4930d89db93fbfe78be164807d5d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-10-05 16:23:44 +00:00
Cheng Chang
d42a620d41 gps: add sepolicy to coredump node am: 1ee114f4d7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/24918561

Change-Id: Id9c4b2ad71d998d96e46b7d0b459241b2f22b98c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-10-05 15:51:45 +00:00
Cheng Chang
1ee114f4d7 gps: add sepolicy to coredump node
Bug: 303343788
Test: b/303343788 verified the SIGABRT/SIGSEGV signal
Change-Id: I5587f632d4cbd2d9210e37c08a19981fb9967a80
2023-10-05 02:47:11 +00:00
Sam Dubey
9af43574a6 Merge "Revert "Allow selinux for gril to use radio ext aidl"" into main 2023-10-04 15:41:04 +00:00
Sam Dubey
1a7ca8326d Merge "Revert "Allow selinux for gril to use radio ext aidl"" into udc-qpr-dev am: befa27b85e am: ff4852d13b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/24940170

Change-Id: I1a1e5d6839fe445b84097b5bb7508e9a4d65f948
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-10-04 15:38:53 +00:00
Sam Dubey
8f7a6dba89 Revert "Allow selinux for gril to use radio ext aidl"
Revert submission 24799507-ak3_ssc_aidl

Reason for revert: Broke next target, b/303392497

Reverted changes: /q/submissionid:24799507-ak3_ssc_aidl

Change-Id: Ib2a84012f953683308b906193e457ef8a479867f
Merged-In: Ib2a84012f953683308b906193e457ef8a479867f
2023-10-04 15:32:19 +00:00
Sam Dubey
ff4852d13b Merge "Revert "Allow selinux for gril to use radio ext aidl"" into udc-qpr-dev am: befa27b85e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/24940170

Change-Id: I284004786847d02e2204cd4522aaa3c4b18a52ad
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-10-04 15:07:44 +00:00
Sam Dubey
befa27b85e Merge "Revert "Allow selinux for gril to use radio ext aidl"" into udc-qpr-dev 2023-10-04 14:34:18 +00:00
Sam Dubey
31d1e1160b Revert "Allow selinux for gril to use radio ext aidl"
Revert submission 24799507-ak3_ssc_aidl

Reason for revert: Broke next target, b/303392497

Reverted changes: /q/submissionid:24799507-ak3_ssc_aidl

Change-Id: Ib2a84012f953683308b906193e457ef8a479867f
2023-10-04 13:11:40 +00:00
Shinru Han
35bef58909 Merge "gps: pixel gnss aidl service (sepolicy)" into udc-qpr-dev am: 4f1985f354 am: 77968195f7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/24498897

Change-Id: If423bc3a872e6596e4748eb548e64614fca38bdd
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-10-04 09:57:50 +00:00
Shinru Han
77968195f7 Merge "gps: pixel gnss aidl service (sepolicy)" into udc-qpr-dev am: 4f1985f354
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/24498897

Change-Id: I4fd76a5167e91da8b74a796882a165627aa2412b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-10-04 09:29:42 +00:00
Shinru Han
4f1985f354 Merge "gps: pixel gnss aidl service (sepolicy)" into udc-qpr-dev 2023-10-04 09:06:22 +00:00
Alan Chen
447a66dd74 Allow selinux for gril to use radio ext aidl am: 2d635d58d3 am: b61356877e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/24847488

Change-Id: Iadf8b8f46f98cff587c5b404adc75759525f3c63
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-10-04 08:54:09 +00:00
Alan Chen
b61356877e Allow selinux for gril to use radio ext aidl am: 2d635d58d3
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/24847488

Change-Id: Id43467a31c048ab95206d2dab355d6e1eceace73
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-10-04 08:24:13 +00:00
Shinru Han
69d9e01e8a gps: pixel gnss aidl service (sepolicy)
avc:  denied  { call } for  scontext=u:r:servicemanager:s0 tcontext=u:r:hal_gnss_pixel:s0 tclass=binder permissive=0
avc:  denied  { call } for  scontext=u:r:hal_gnss_pixel:s0 tcontext=u:r:hal_gnss_default:s0 tclass=binder permissive=0
avc:  denied  { call } for  scontext=u:r:hal_gnss_default:s0 tcontext=u:r:hal_gnss_pixel:s0 tclass=binder permissive=0
avc:  denied  { read } for  name="modem_state" dev="sysfs" ino=66325 scontext=u:r:hal_gnss_pixel:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=1
avc:  denied  { open } for  path="/sys/devices/platform/cpif/modem_state" dev="sysfs" ino=66325 scontext=u:r:hal_gnss_pixel:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=1
avc:  denied  { getattr } for  path="/sys/devices/platform/cpif/modem_state" dev="sysfs" ino=66325 scontext=u:r:hal_gnss_pixel:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=1

Bug: 298924540
Test: No avc deny
Change-Id: I77ec1cb171781dd3c671a975a5c049a48d5bcccb
2023-10-03 08:53:15 +00:00
Alan Chen
2d635d58d3 Allow selinux for gril to use radio ext aidl
Test: manual - verified there are no avc denied logs
Bug: 285459428
Change-Id: I38c88d82860f37e34772b786a8940db02dc17ac6
2023-10-03 05:22:32 +00:00
Edwin Tung
ca875aa18e gps: gnss aidl service (sepolicy) am: 76686f69d9 am: 325b59f289
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/24896011

Change-Id: I00e3ba4fde73cb1ff7c6b29bf5ce1f232b098acb
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-10-02 11:12:30 +00:00
Edwin Tung
325b59f289 gps: gnss aidl service (sepolicy) am: 76686f69d9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/24896011

Change-Id: I73578c52b62fd16cbf662fde3ee6e5a0205d3bc7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-10-02 10:06:30 +00:00
Edwin Tung
76686f69d9 gps: gnss aidl service (sepolicy)
avc:  denied  { read } for  name="u:object_r:vendor_gps_prop:s0" dev="tmpfs" ino=372 scontext=u:r:hal_gnss_default:s0 tcontext=u:object_r:vendor_gps_prop:s0 tclass=file permissive=0

Bug: 295810526
Test: No avc denied
Change-Id: I686cd19143dc58706af8b43a4b87a73e23a43fd3
2023-09-29 11:59:47 +08:00
Desmond Huang
d6637d93a5 Relocate common tracking denial entries
Bug: 299029620
Change-Id: Id520cd37bedb9b7507396f0fae24e4b6f4fe3dbf
2023-09-15 03:39:14 +00:00
Desmond Huang
f081cedad0 Remove obsolete entries
Bug: 299029620
Change-Id: I6edb77911ee0d63188bf1aa54d4162480e9a7f71
2023-09-15 03:36:57 +00:00
Edwin Tung
3efe11595b Merge "gps: remove permissive gnssd hal_gnss_default" into udc-qpr-dev am: c3faae21ea am: 0a3ae091b7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/24687594

Change-Id: Ia1b85d95b6da331a8e800642a2e95ee460560461
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-09-11 18:07:25 +00:00
Edwin Tung
0a3ae091b7 Merge "gps: remove permissive gnssd hal_gnss_default" into udc-qpr-dev am: c3faae21ea
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/24687594

Change-Id: Ie1321e117e10cbdbf269ad0c1fffe128140db181
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-09-11 17:17:07 +00:00
Edwin Tung
c3faae21ea Merge "gps: remove permissive gnssd hal_gnss_default" into udc-qpr-dev 2023-09-11 16:43:34 +00:00
Wilson Sung
fa64780395 Update SELinux error am: dfe9efa9ff am: a3021b472e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/24687591

Change-Id: I5a368cf822e7370a0efef87ee0b58cc2a0765bce
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-09-08 07:46:50 +00:00
Wilson Sung
a3021b472e Update SELinux error am: dfe9efa9ff
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/24687591

Change-Id: I3d9f65f78f2256b8921d6c714a33e4ff1ce6f648
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-09-08 06:53:46 +00:00
Edwin Tung
3ffbeda496 gps: remove permissive gnssd hal_gnss_default
Bug: 265391808
Test: gnss works
Change-Id: Ib4f2dd73255d333930a4d8ad0884b3f54c5f0f0a
2023-09-08 12:04:09 +08:00
Wilson Sung
dfe9efa9ff Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 299553682
Bug: 299553227
Change-Id: I1a40d2c1cff2ea5e252047601166584546349e67
2023-09-08 11:35:04 +08:00
Edwin Tung
96f5354183 gps: allow vendor_init to set gps debug prop am: f4405c835b am: 8e4aea0b4f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/24658030

Change-Id: I406844e11fac41e75f462ace151469479bf2ea18
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-09-05 09:43:21 +00:00
Edwin Tung
8e4aea0b4f gps: allow vendor_init to set gps debug prop am: f4405c835b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/24658030

Change-Id: I5a8b3f5a63edd3fe5c62b718c8866308396ec5ca
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-09-05 08:46:37 +00:00
Edwin Tung
f4405c835b gps: allow vendor_init to set gps debug prop
Bug: 298871633

Test: build pass, check sepolicy
and gps log in bugreport

Change-Id: Ice46d0ae5ddd0b7e7362684917b0b0e7c7183db9
2023-09-05 13:05:47 +08:00
Wilson Sung
563b666341 Update SELinux error am: 5ad65f26f7 am: f9695506b3
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/24329845

Change-Id: I7ef96abfe999b8469e67493be4ebb0eb9b5ab191
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-09 04:14:21 +00:00
Wilson Sung
f9695506b3 Update SELinux error am: 5ad65f26f7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/24329845

Change-Id: Id0b4eee2af0a7701aa6b87e00972ce58c3925aee
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-09 03:33:34 +00:00
Edwin Tung
3667cf9c9c gps: remove unused sepolicy am: 10251376c0 am: 0b3231bb54
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/24325865

Change-Id: I13421764f5fa0de0b8bf8745f03883079f4878fc
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-08 10:28:16 +00:00
Wilson Sung
5ad65f26f7 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 294967729
Change-Id: I3b17e72e9364c57458423142f3509a3dd8425c69
2023-08-08 17:48:43 +08:00
Edwin Tung
0b3231bb54 gps: remove unused sepolicy am: 10251376c0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/24325865

Change-Id: I7d555cdfa521a24d891a06c804c464f05b681e23
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-08 09:46:16 +00:00
Edwin Tung
10251376c0 gps: remove unused sepolicy
Bug: 246482115
Test: gps works
Change-Id: I43ba2a4dad4034b953ed6608c93a5ff1abe16bd2
2023-08-07 18:10:02 +08:00
Edwin Tung
833002d9c8 gps: Add sepolicy for gps am: a648924b14 am: 9d0009c25a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/24319937

Change-Id: I1189b89215fe41f4ff4912a455405f2026efac07
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-07 04:19:26 +00:00
Edwin Tung
9d0009c25a gps: Add sepolicy for gps am: a648924b14
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/24319937

Change-Id: Iafa1f7bb4c81fce27739033640aff8562795d870
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-07 03:38:08 +00:00
Edwin Tung
a648924b14 gps: Add sepolicy for gps
Bug: 294482059
Bug: 294481452
Bug: 294175645

Test: Fix data/vendor/gps avc denied
Change-Id: I3a93b7b8c8e6aff3fbd114fa5bf49ed0f8140258
2023-08-04 17:00:56 +08:00
Edwin Tung
12b5cec067 Add sepolicy for gnssd am: e19e985013 am: 0296e8a3fc
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/24061446

Change-Id: I6c9331a3b8bfc4f4e448f0214c3e46ec74232e10
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-17 06:14:13 +00:00