Commit graph

63 commits

Author SHA1 Message Date
Sam Dubey
ff4852d13b Merge "Revert "Allow selinux for gril to use radio ext aidl"" into udc-qpr-dev am: befa27b85e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/24940170

Change-Id: I284004786847d02e2204cd4522aaa3c4b18a52ad
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-10-04 15:07:44 +00:00
Sam Dubey
befa27b85e Merge "Revert "Allow selinux for gril to use radio ext aidl"" into udc-qpr-dev 2023-10-04 14:34:18 +00:00
Sam Dubey
31d1e1160b Revert "Allow selinux for gril to use radio ext aidl"
Revert submission 24799507-ak3_ssc_aidl

Reason for revert: Broke next target, b/303392497

Reverted changes: /q/submissionid:24799507-ak3_ssc_aidl

Change-Id: Ib2a84012f953683308b906193e457ef8a479867f
2023-10-04 13:11:40 +00:00
Shinru Han
77968195f7 Merge "gps: pixel gnss aidl service (sepolicy)" into udc-qpr-dev am: 4f1985f354
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/24498897

Change-Id: I4fd76a5167e91da8b74a796882a165627aa2412b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-10-04 09:29:42 +00:00
Shinru Han
4f1985f354 Merge "gps: pixel gnss aidl service (sepolicy)" into udc-qpr-dev 2023-10-04 09:06:22 +00:00
Alan Chen
b61356877e Allow selinux for gril to use radio ext aidl am: 2d635d58d3
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/24847488

Change-Id: Id43467a31c048ab95206d2dab355d6e1eceace73
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-10-04 08:24:13 +00:00
Shinru Han
69d9e01e8a gps: pixel gnss aidl service (sepolicy)
avc:  denied  { call } for  scontext=u:r:servicemanager:s0 tcontext=u:r:hal_gnss_pixel:s0 tclass=binder permissive=0
avc:  denied  { call } for  scontext=u:r:hal_gnss_pixel:s0 tcontext=u:r:hal_gnss_default:s0 tclass=binder permissive=0
avc:  denied  { call } for  scontext=u:r:hal_gnss_default:s0 tcontext=u:r:hal_gnss_pixel:s0 tclass=binder permissive=0
avc:  denied  { read } for  name="modem_state" dev="sysfs" ino=66325 scontext=u:r:hal_gnss_pixel:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=1
avc:  denied  { open } for  path="/sys/devices/platform/cpif/modem_state" dev="sysfs" ino=66325 scontext=u:r:hal_gnss_pixel:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=1
avc:  denied  { getattr } for  path="/sys/devices/platform/cpif/modem_state" dev="sysfs" ino=66325 scontext=u:r:hal_gnss_pixel:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=1

Bug: 298924540
Test: No avc deny
Change-Id: I77ec1cb171781dd3c671a975a5c049a48d5bcccb
2023-10-03 08:53:15 +00:00
Alan Chen
2d635d58d3 Allow selinux for gril to use radio ext aidl
Test: manual - verified there are no avc denied logs
Bug: 285459428
Change-Id: I38c88d82860f37e34772b786a8940db02dc17ac6
2023-10-03 05:22:32 +00:00
Edwin Tung
325b59f289 gps: gnss aidl service (sepolicy) am: 76686f69d9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/24896011

Change-Id: I73578c52b62fd16cbf662fde3ee6e5a0205d3bc7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-10-02 10:06:30 +00:00
Edwin Tung
76686f69d9 gps: gnss aidl service (sepolicy)
avc:  denied  { read } for  name="u:object_r:vendor_gps_prop:s0" dev="tmpfs" ino=372 scontext=u:r:hal_gnss_default:s0 tcontext=u:object_r:vendor_gps_prop:s0 tclass=file permissive=0

Bug: 295810526
Test: No avc denied
Change-Id: I686cd19143dc58706af8b43a4b87a73e23a43fd3
2023-09-29 11:59:47 +08:00
Edwin Tung
0a3ae091b7 Merge "gps: remove permissive gnssd hal_gnss_default" into udc-qpr-dev am: c3faae21ea
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/24687594

Change-Id: Ie1321e117e10cbdbf269ad0c1fffe128140db181
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-09-11 17:17:07 +00:00
Edwin Tung
c3faae21ea Merge "gps: remove permissive gnssd hal_gnss_default" into udc-qpr-dev 2023-09-11 16:43:34 +00:00
Wilson Sung
a3021b472e Update SELinux error am: dfe9efa9ff
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/24687591

Change-Id: I3d9f65f78f2256b8921d6c714a33e4ff1ce6f648
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-09-08 06:53:46 +00:00
Edwin Tung
3ffbeda496 gps: remove permissive gnssd hal_gnss_default
Bug: 265391808
Test: gnss works
Change-Id: Ib4f2dd73255d333930a4d8ad0884b3f54c5f0f0a
2023-09-08 12:04:09 +08:00
Wilson Sung
dfe9efa9ff Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 299553682
Bug: 299553227
Change-Id: I1a40d2c1cff2ea5e252047601166584546349e67
2023-09-08 11:35:04 +08:00
Edwin Tung
8e4aea0b4f gps: allow vendor_init to set gps debug prop am: f4405c835b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/24658030

Change-Id: I5a8b3f5a63edd3fe5c62b718c8866308396ec5ca
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-09-05 08:46:37 +00:00
Edwin Tung
f4405c835b gps: allow vendor_init to set gps debug prop
Bug: 298871633

Test: build pass, check sepolicy
and gps log in bugreport

Change-Id: Ice46d0ae5ddd0b7e7362684917b0b0e7c7183db9
2023-09-05 13:05:47 +08:00
Wilson Sung
f9695506b3 Update SELinux error am: 5ad65f26f7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/24329845

Change-Id: Id0b4eee2af0a7701aa6b87e00972ce58c3925aee
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-09 03:33:34 +00:00
Wilson Sung
5ad65f26f7 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 294967729
Change-Id: I3b17e72e9364c57458423142f3509a3dd8425c69
2023-08-08 17:48:43 +08:00
Edwin Tung
0b3231bb54 gps: remove unused sepolicy am: 10251376c0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/24325865

Change-Id: I7d555cdfa521a24d891a06c804c464f05b681e23
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-08 09:46:16 +00:00
Edwin Tung
10251376c0 gps: remove unused sepolicy
Bug: 246482115
Test: gps works
Change-Id: I43ba2a4dad4034b953ed6608c93a5ff1abe16bd2
2023-08-07 18:10:02 +08:00
Edwin Tung
9d0009c25a gps: Add sepolicy for gps am: a648924b14
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/24319937

Change-Id: Iafa1f7bb4c81fce27739033640aff8562795d870
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-07 03:38:08 +00:00
Edwin Tung
a648924b14 gps: Add sepolicy for gps
Bug: 294482059
Bug: 294481452
Bug: 294175645

Test: Fix data/vendor/gps avc denied
Change-Id: I3a93b7b8c8e6aff3fbd114fa5bf49ed0f8140258
2023-08-04 17:00:56 +08:00
Edwin Tung
0296e8a3fc Add sepolicy for gnssd am: e19e985013
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/24061446

Change-Id: I09ac89df355d34b6a91b7091e24b3a768f19cbd7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-17 05:34:06 +00:00
Edwin Tung
e19e985013 Add sepolicy for gnssd
Bug: 265391808
Test: No avc denied
Change-Id: Ib4645bc0f26ac261c7aae6f1b621303e88e09690
2023-07-17 11:32:31 +08:00
Treehugger Robot
972964a0e6 Merge "Update SELinux error" into udc-qpr-dev am: 309ef096ac
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/23891666

Change-Id: I8899f5f6682c8e7f7807a73103eaa18a99f60c83
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-10 07:54:45 +00:00
Treehugger Robot
309ef096ac Merge "Update SELinux error" into udc-qpr-dev 2023-07-10 07:06:55 +00:00
Ken Yang
bcc54f2632 SELinux: fix the avc denial am: c5e2845283
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/23901401

Change-Id: I2d67ca26c680ca1625dd20e16e92d5aa730ce5ea
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-06 07:43:45 +00:00
Ken Yang
c5e2845283 SELinux: fix the avc denial
Bug: 289856364
Change-Id: Ib3b1ea0b578f72a422be6f94d94cf8ddf5523ae2
Signed-off-by: Ken Yang <yangken@google.com>
2023-07-05 22:47:38 +00:00
Wilson Sung
f22f1eb0ee Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 289856364
Bug: 289856386
Bug: 289856465
Change-Id: I53cc55e152912c0a94957e216e4a3ea6dde3133c
2023-07-04 11:17:02 +08:00
Darren Hsu
3a2e4957af sepolicy: allow system_suspend to read gnss sysfs am: 566095b9ae
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/23840927

Change-Id: I071d9807da21adb58b595da33e0fd0b3207a9717
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-30 03:14:00 +00:00
Darren Hsu
566095b9ae sepolicy: allow system_suspend to read gnss sysfs
avc:  denied  { read } for  name="wakeup61" dev="sysfs" ino=65863
scontext=u:r:system_suspend:s0 tcontext=u:object_r:sysfs:s0 tclass=dir
permissive=0 bug=b/288984031

Bug: 288984031
Test: capture a bug report and check there is no
avc denial related to gnss
Change-Id: Iab3e835ae1d3b874eb8acbe18278b5ba1d7cb126
Signed-off-by: Darren Hsu <darrenhsu@google.com>
2023-06-30 07:23:11 +08:00
Ken Yang
80533d0d47 SELinux: fix avc denials am: 560e733bec
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/23846313

Change-Id: I6941f67c119a110b722ae4afc439834e0948a875
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-29 07:39:52 +00:00
Ken Yang
560e733bec SELinux: fix avc denials
Fix the avc denials for sysfs_wakeup

Bug: 288049074
Change-Id: Ibc0d59597373d9ec378c90c7b372876b846b4338
Signed-off-by: Ken Yang <yangken@google.com>
2023-06-29 06:59:30 +00:00
Android Culprit Assistant
b7766afa7f Revert "SELinux: fix avc denials" am: 8cc94857ed
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/23844494

Change-Id: I20a1c981b0bb572f5225579854ebab6ba7f17657
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-28 14:04:22 +00:00
Android Culprit Assistant
8cc94857ed Revert "SELinux: fix avc denials"
This revert was created by Android Culprit Assistant. The culprit was identified in the following culprit search session (http://go/aca-get/ad8a70f9-8859-4f13-b4b4-2a7903a68e85).

Change-Id: Id230b3dc859469b64df2245efd82d3a92cefafe4
2023-06-28 12:59:43 +00:00
Ken Yang
7a9789104c SELinux: fix avc denials am: 253a4052cc
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/23767291

Change-Id: I085c778b45c9d84a34ec8c744acb6d597c439edb
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-28 03:48:00 +00:00
Ken Yang
253a4052cc SELinux: fix avc denials
Fix the avc denials fof sysfs_wakeup

Bug: 288049074
Change-Id: I646047b9114884a33cc36035eaa1d1d5d9f99d1c
Signed-off-by: Ken Yang <yangken@google.com>
2023-06-28 02:30:48 +00:00
Wilson Sung
df6262d0a6 Update SELinux error am: 6557908358
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/23824283

Change-Id: If39e356cd72cf15f1325f4ba6fcc50ded15a7bf3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-27 05:52:37 +00:00
Wilson Sung
6557908358 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 288984267
Bug: 288984031
Bug: 288983920
Change-Id: Ic51ed7b691493498c09744903152bb714e3ee805
2023-06-27 11:52:02 +08:00
Wilson Sung
07a64067a6 Update SELinux error am: c1fd684e0f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/23740932

Change-Id: I22cd43662e3f8a9cd824e27f4718b3baad8fffb9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-21 08:47:50 +00:00
Wilson Sung
c1fd684e0f Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 288049074
Bug: 288049372
Change-Id: Ia62a97443649d8ee15f8907ad99251b7c2a3b316
2023-06-20 16:08:13 +08:00
Colin Ko
ce4f564857 Allow vendor_init to set camera debug prop am: 1605f391a2 am: 1ccc2906ef
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/23688444

Change-Id: Iad9e12ef9b803d33dbff7aede974e557d90ae9a1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-14 09:28:24 +00:00
Colin Ko
7b0675a3b8 Allow vendor_init to set camera debug prop am: 1605f391a2 am: 626b85a71a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/23688444

Change-Id: I121ed92e2d163c50da98c1f67ea910a9c7e2fcab
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-14 09:22:26 +00:00
Colin Ko
1ccc2906ef Allow vendor_init to set camera debug prop am: 1605f391a2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/23688444

Change-Id: I3cf62a4de16608a6a0f28bad9c95541fc125a98f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-14 08:40:37 +00:00
Colin Ko
626b85a71a Allow vendor_init to set camera debug prop am: 1605f391a2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/23688444

Change-Id: I67021e871792667654a965e151bc5ef43b3e81ab
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-14 08:36:23 +00:00
Colin Ko
1605f391a2 Allow vendor_init to set camera debug prop
Bug: 286780112
Test: build pass, check sepolicy
Change-Id: I67d940524e4d6d14d9d589230dacad1778fa48ab
2023-06-14 06:22:57 +00:00
Edwin Tung
54cc662804 Add sepolicy for gnssd am: c2b07bc5f6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/23517406

Change-Id: Ibae7a9ff10eb9b0c5ca38fd73df1c0f5d8a5d71e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-06-05 05:15:38 +00:00
Edwin Tung
c2b07bc5f6 Add sepolicy for gnssd
Bug: 265391808
Test: build pass
Change-Id: I27d4ebe455967ffd732cea05d7375fbe7be5ab62
2023-06-05 10:43:33 +08:00
Edwin Tung
4a1768e884 Add sepolicy for gnssd am: 1be1e15c26
Original change: https://googleplex-android-review.googlesource.com/c/device/google/akita-sepolicy/+/23056927

Change-Id: Ifc5c66fec25559ab6bbc8d45c51300ba9a40ba41
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-10 01:56:09 +00:00