Commit graph

102 commits

Author SHA1 Message Date
Jenny Ho
05a2ff9ae0 remove tracking denial of device chr_file am: 3a92d3d265 am: edce76c2b1
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/20733206

Change-Id: I93103c93ffe596a8bdd076dc5b281f889060909d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-16 08:04:34 +00:00
Jenny Ho
edce76c2b1 remove tracking denial of device chr_file am: 3a92d3d265
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/20733206

Change-Id: I51af87a6a17323a334cf3408e5dd324a097b5571
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-16 07:26:40 +00:00
Jenny Ho
3a92d3d265 remove tracking denial of device chr_file
Bug: 254164096
Change-Id: I300d092df3610f29f05ca65a89eba5459ca0063a
Signed-off-by: Jenny Ho <hsiufangho@google.com>
2022-12-14 15:21:50 +08:00
Chase Wu
f4be42ae00 Remove sepolicy for vibrator manager service am: c02424796d am: cbfaaeea39
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/20610806

Change-Id: If5c216b5bbcbfda16712a8e8421c0498a35b0900
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-13 11:26:50 +00:00
Chase Wu
cbfaaeea39 Remove sepolicy for vibrator manager service am: c02424796d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/20610806

Change-Id: I558a8250352ec221945eafaaa5f1054488d94ea5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-13 10:52:38 +00:00
Chase Wu
c02424796d Remove sepolicy for vibrator manager service
Bug: 260090235
Test: check avc error
Change-Id: I2cb9f9efe849ae6e7fb9b1b5aba2f92a3346af6d
Signed-off-by: Chase Wu <chasewu@google.com>
2022-12-02 01:09:45 +08:00
Mason Wang
6b826a850d [automerger skipped] Allow dumpstate to access touch vendor nodes[DO NOT MERGE] am: 3c82f575b9 am: 7184709e5f -s ours
am skip reason: subject contains skip directive

Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/20541991

Change-Id: I5b92d44c11fc348616bee7fc2384dcb49d99d833
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-11-28 02:21:52 +00:00
Mason Wang
7184709e5f Allow dumpstate to access touch vendor nodes[DO NOT MERGE] am: 3c82f575b9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/20541991

Change-Id: I0b3d46eab39ba1471b751cdd2810fa0cf27fe723
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-11-28 01:53:24 +00:00
Mason Wang
3c82f575b9 Allow dumpstate to access touch vendor nodes[DO NOT MERGE]
Fix following avc denial log:
avc: denied { read } for name="driver_test" dev="proc" ino=4026535583 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:proc:s0 tclass=file permissive=1 bug=b/240632721
avc: denied { write } for name="driver_test" dev="proc" ino=4026535583 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:proc:s0 tclass=file permissive=1 bug=b/240632721
avc: denied { open } for path="/proc/fts/driver_test" dev="proc" ino=4026535583 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:proc:s0 tclass=file permissive=1 bug=b/240632721
avc: denied { open } for path="/sys/devices/platform/10950000.spi/spi_master/spi6/spi6.0/appid" dev="sysfs" ino=110523 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=1 bug=b/240632721
avc: denied { open } for path="/sys/devices/platform/10950000.spi/spi_master/spi6/spi6.0/stm_fts_cmd" dev="sysfs" ino=110529 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=1 bug=b/240632721
avc: denied { open } for path="/proc/fts_ext/driver_test" dev="proc" ino=4026535585 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:proc:s0 tclass=file permissive=1 bug=b/240632721
avc: denied { write } for name="stm_fts_cmd" dev="sysfs" ino=113133 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=1 bug=b/240632721
avc: denied { read } for name="stm_fts_cmd" dev="sysfs" ino=113133 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=1 bug=b/240632721
avc: denied { read } for name="appid" dev="sysfs" ino=108992 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=0 bug=b/240632721


Bug: 226475119
Bug: 254164096
Test: There are no above avc denial logs.
Change-Id: I0a136a7e259640e3e13ea66c945251cf26878b33
2022-11-24 15:35:16 +08:00
Nicole Lee
50e095c30d Revert "Allow dumpstate to access touch vendor nodes" am: d6fe8df131 am: bb99a93833
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/20519118

Change-Id: I92b3ab14af65c34621046e42dac72e091c59dda1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-11-22 07:22:33 +00:00
Nicole Lee
bb99a93833 Revert "Allow dumpstate to access touch vendor nodes" am: d6fe8df131
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/20519118

Change-Id: I054a4a0ae0d8136e50be58276ff860294096ba7e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-11-22 06:47:10 +00:00
Nicole Lee
d6fe8df131 Revert "Allow dumpstate to access touch vendor nodes"
This reverts commit b1d4e8ab2f.

Reason for revert: DroidMonitor: Potential culprit for Bug 260019672 - verifying through ABTD before revert submission. This is part of the standard investigation process, and does not mean your CL will be reverted.

Change-Id: I8c3bf9982eb9c163e73e75624fd3265ddaa1de95
2022-11-22 06:02:47 +00:00
eddielan
7fd47dc7fb sepolicy: Allow fingerprint to access fwk hwservice am: f544a5a651 am: 25e250aad0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/20441648

Change-Id: I60f5ed42cc20df7c62f0212b68f4a4d0137985b5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-11-17 04:24:06 +00:00
eddielan
25e250aad0 sepolicy: Allow fingerprint to access fwk hwservice am: f544a5a651
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/20441648

Change-Id: I477e36aeecb337216b8bdbe656370885a2699733
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-11-17 03:29:38 +00:00
eddielan
f544a5a651 sepolicy: Allow fingerprint to access fwk hwservice
11-11 19:57:30.203   464   464 E SELinux : avc:
denied  { find } for interface=android.frameworks.sensorservice::ISensorManager
sid=u:r:hal_fingerprint_capacitance:s0 pid=903
scontext=u:r:hal_fingerprint_capacitance:s0
tcontext=u:object_r:fwk_sensor_hwservice:s0
tclass=hwservice_manager permissive=0

Bug: 258783592
Test: Build pass
Change-Id: I58a31c04cbb45ab12b0bf42a10c57ddf4f065ee7
2022-11-11 20:10:20 +08:00
Chase Wu
6fb0d40d35 add sepolicy for vibrator manager service am: 6c42229dcc am: a8a51be9ae
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/18350088

Change-Id: I3f1a2b791dabc0c323e89b9a763be0ff7bc12b03
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-11-03 10:10:10 +00:00
Chase Wu
a8a51be9ae add sepolicy for vibrator manager service am: 6c42229dcc
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/18350088

Change-Id: Ib7de5bab2bda145de85e42607c0fdf32862c5431
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-11-03 08:08:46 +00:00
Chase Wu
6c42229dcc add sepolicy for vibrator manager service
Bug: 181615889
Test: Run all test suites
Signed-off-by: chasewu <chasewu@google.com>
Change-Id: Ie9e3c86b01afb26557ae69ead813dd123b4df91b
2022-11-03 12:14:03 +08:00
Mason Wang
98c3066632 Allow dumpstate to access touch vendor nodes am: b1d4e8ab2f am: 1d9860e41c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/20305443

Change-Id: I5703d35cc715b30a92fe2632f62fde743e2a8fce
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-10-28 10:14:40 +00:00
Mason Wang
1d9860e41c Allow dumpstate to access touch vendor nodes am: b1d4e8ab2f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/20305443

Change-Id: I0b297e88ad40f6bba61423e203be01297b486ebb
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-10-28 09:00:57 +00:00
Mason Wang
b1d4e8ab2f Allow dumpstate to access touch vendor nodes
Fix following avc denial log:
avc: denied { write } for name="stm_fts_cmd" dev="sysfs" ino=113133 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=1 bug=b/240632721
avc: denied { open } for path="/sys/devices/platform/10950000.spi/spi_master/spi6/spi6.0/stm_fts_cmd" dev="sysfs" ino=113133 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=1 bug=b/240632721
avc: denied { read } for name="stm_fts_cmd" dev="sysfs" ino=113133 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=1 bug=b/240632721
avc: denied { read } for name="driver_test" dev="proc" ino=4026535565 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:proc:s0 tclass=file permissive=0 bug=b/240632721
avc: denied { read } for name="appid" dev="sysfs" ino=108992 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=0 bug=b/240632721


Bug: 226475119
Bug: 254164096
Test: There are no above avc denial logs.
Change-Id: Ie01104ebfb94154584d9d466cb295095eb634f48
2022-10-28 12:44:25 +08:00
TreeHugger Robot
b651631851 Merge "sepolicy: remove tracking bugs for PowerStatsHAL and SystemSuspend" into tm-qpr-dev am: 9219b31d13 am: 2157e5e3b0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/20279296

Change-Id: Iec0c88d5d2a0ce637fbddc52a50cb392c10a10ea
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-10-27 04:37:55 +00:00
TreeHugger Robot
2157e5e3b0 Merge "sepolicy: remove tracking bugs for PowerStatsHAL and SystemSuspend" into tm-qpr-dev am: 9219b31d13
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/20279296

Change-Id: I3e6a9c16df76bd8d859f948fe77e56a9bdf42a5e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-10-27 04:01:31 +00:00
eddielan
68117d5f56 Fix FPS servicemanager sepolicy issue am: ef12403d44 am: 7d9bbe844f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/20271738

Change-Id: I19c42155bb11f8502f8bcb14571ad3b29db4a5d1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-10-27 03:48:47 +00:00
TreeHugger Robot
9219b31d13 Merge "sepolicy: remove tracking bugs for PowerStatsHAL and SystemSuspend" into tm-qpr-dev 2022-10-27 03:26:15 +00:00
eddielan
7d9bbe844f Fix FPS servicemanager sepolicy issue am: ef12403d44
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/20271738

Change-Id: Ia4a7b299d28f6105d98e2febe1116b24a68024de
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-10-27 03:12:02 +00:00
Darren Hsu
577965ec5f sepolicy: remove tracking bugs for PowerStatsHAL and SystemSuspend
b/240632970 is not reproducible on TD3A.221020.001.
b/240632822 has been fixed by ag/20209545.

Bug: 240632970
Bug: 240632822
Test: Capture bugreport and check no avc denails
Change-Id: I9a2290e2857415c3edecd98b88af6382a42530ff
Signed-off-by: Darren Hsu <darrenhsu@google.com>
2022-10-26 17:31:17 +08:00
eddielan
ef12403d44 Fix FPS servicemanager sepolicy issue
10-25 03:25:07.740   429   429 I auditd  : type=1400 audit(0.0:4):
avc: denied { call } for comm="servicemanager"
scontext=u:r:servicemanager:s0
tcontext=u:r:hal_fingerprint_capacitance:s0
tclass=binder permissive=0

Bug: 253533883
Test: make selinux_policy -j128 && check log on device
Change-Id: Ic3007d53398eb9770466c24b3aa49c1325bdbb47
2022-10-26 12:01:36 +08:00
TreeHugger Robot
ff01c72b31 Merge "sepolicy: add sysfs_wakeup labels for System Suspend" into tm-qpr-dev am: f2b9557796 am: d0b886a5b5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/20209545

Change-Id: I86a311a85907784a3deaf192e31c0c94340844a4
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-10-19 10:36:57 +00:00
TreeHugger Robot
d0b886a5b5 Merge "sepolicy: add sysfs_wakeup labels for System Suspend" into tm-qpr-dev am: f2b9557796
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/20209545

Change-Id: Icbdf3b3b7f721b5ef0b6222d0e18ec39cc6ca200
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-10-19 09:46:40 +00:00
TreeHugger Robot
f2b9557796 Merge "sepolicy: add sysfs_wakeup labels for System Suspend" into tm-qpr-dev 2022-10-19 09:18:11 +00:00
eddielan
e8282686e4 Remove fingerprint tracking bug am: 2fef9efcc4 am: 9326d9fa80
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/20194455

Change-Id: I508fc7b8dcf9996632ef2e370524c7fc4a372a45
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-10-18 03:47:19 +00:00
Darren Hsu
99f9cd6a45 sepolicy: add sysfs_wakeup labels for System Suspend
Bug: 253980198
Test: run vts -m SuspendSepolicyTests
Change-Id: Ie58c35b37ad0a904d0292d2be9092f82b02d514b
Signed-off-by: Darren Hsu <darrenhsu@google.com>
2022-10-18 11:39:51 +08:00
eddielan
9326d9fa80 Remove fingerprint tracking bug am: 2fef9efcc4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/20194455

Change-Id: I6f5973e3e41d6998a8bcbeaa822548e43eb07f54
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-10-18 03:15:45 +00:00
eddielan
2fef9efcc4 Remove fingerprint tracking bug
Patch was merged on ag/19457937

Bug: 240633068
Test: make selinux_policy -j128
Change-Id: Ic25e266701993fadc51b12c25c9a170c38e29785
2022-10-17 15:09:24 +08:00
Ted Lin
8d46affec7 Remove bug mapping in the tracking denials am: 5126a011d0 am: a054dec9fc
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/19880945

Change-Id: I6395da93e92ac6011a30d59c0eeaadb0774d78e6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-09-08 07:40:05 +00:00
Ted Lin
a054dec9fc Remove bug mapping in the tracking denials am: 5126a011d0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/19880945

Change-Id: Iba4f8821193619d447145f8cef2148b0097dd2e9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-09-08 07:09:47 +00:00
Ted Lin
5126a011d0 Remove bug mapping in the tracking denials
Bug: 240632860
Test: Check the bugreport
Signed-off-by: Ted Lin <tedlin@google.com>
Change-Id: Ic4c68fe39b3e7e82cf9edcb6b594b598f5ba9499
2022-09-07 16:50:57 +08:00
Adam Shih
e503f72b10 Update error on ROM 8979803 am: 454e019bee am: 4761cbe496
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/19738804

Change-Id: I4164cc84bc93edc8b08d6cbad83d492c4f3e372c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-08-25 06:27:11 +00:00
Adam Shih
4761cbe496 Update error on ROM 8979803 am: 454e019bee
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/19738804

Change-Id: Iba8252bc53919aa1f65658a84cebaa914913230c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-08-25 05:49:17 +00:00
Adam Shih
454e019bee Update error on ROM 8979803
Bug: 240632860
Test: SELinuxUncheckedDenialBootTest
Change-Id: Ie192b157e89f86fe36b99202e6ab8677a55c7cee
2022-08-25 10:52:53 +08:00
Wasb Liu
d36e2db35c Add sepolicy for dual_batt_gauge power supply am: 2dcb7cc94f am: 913839b663
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/19711294

Change-Id: Ieb6af9f83457d34d1763f34f2f0aaa519a3b889b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-08-24 08:52:29 +00:00
Wasb Liu
913839b663 Add sepolicy for dual_batt_gauge power supply am: 2dcb7cc94f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/19711294

Change-Id: I2483b95415b062d883bce62b25418a0920789e55
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-08-24 08:23:16 +00:00
Wasb Liu
2dcb7cc94f Add sepolicy for dual_batt_gauge power supply
08-23 02:45:54.456   860   860 I auditd  : type=1400 audit(0.0:4): avc: denied { read } for comm="android.hardwar" name="type" dev="sysfs" ino=100372 scontext=u:r:hal_health_default:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=0

Bug: 243491187
Test: reboot device and check the avc
Signed-off-by: Wasb Liu <wasbliu@google.com>
Change-Id: I7600c816e743fc91afaf66db00ba332229b21e28
2022-08-24 05:01:15 +00:00
Ted Lin
533b9f2d8c Merge "Remove bug mapping in the tracking denials" into tm-qpr-dev am: 1ef6c24de8 am: bbb3fc3708
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/19500898

Change-Id: I4e15b6aa509065db3d36ea61bee0fb10f02743df
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-08-19 08:21:28 +00:00
Ted Lin
bbb3fc3708 Merge "Remove bug mapping in the tracking denials" into tm-qpr-dev am: 1ef6c24de8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/19500898

Change-Id: I5ebf6cf1afb86cf4c5b0f9844d3f9262a3497a47
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-08-19 08:02:16 +00:00
Ted Lin
1ef6c24de8 Merge "Remove bug mapping in the tracking denials" into tm-qpr-dev 2022-08-19 07:36:47 +00:00
TreeHugger Robot
bbde11073f Merge "Revert "Update SELinux error"" into tm-qpr-dev am: e334d5ec9f am: 739043b7fc
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/19560940

Change-Id: Ie10c596c904d2506c0ea4221014e22d1063a04fa
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-08-09 08:29:39 +00:00
TreeHugger Robot
739043b7fc Merge "Revert "Update SELinux error"" into tm-qpr-dev am: e334d5ec9f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/19560940

Change-Id: I76f2aad0142c3baed60b188429a16aa8795fa106
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-08-09 08:02:11 +00:00
TreeHugger Robot
e334d5ec9f Merge "Revert "Update SELinux error"" into tm-qpr-dev 2022-08-09 07:37:37 +00:00