Commit graph

225 commits

Author SHA1 Message Date
Liana Kazanova
1979e8df0a Revert "Add device specific entry back."
Revert submission 26288713-twoshay-sepolicy-24

Reason for revert: DroidMonitor: Potential culprit for b/327235315 - verifying through ABTD before revert submission. This is part of the standard investigation process, and does not mean your CL will be reverted.

Bug:327235315

Reverted changes: /q/submissionid:26288713-twoshay-sepolicy-24

Change-Id: I250fd1c8415c3c865bffa4504c8c290c0d49fddb
2024-02-27 21:20:02 +00:00
Mark Chang
836da8022d Add device specific entry back.
Bug: 325422902
Test: Manual, system booted without sepolicy denied error.
Change-Id: I10132c2da0b6b3b76e67ba07a6692f41a6a1a58a
Signed-off-by: Mark Chang <changmark@google.com>
2024-02-19 05:46:59 +00:00
Jacky Liu
2bc710e44c Update i2c device paths
Update i2c device paths with static bus numbers.
Remove entries which are already in gs201-sepolicy.

Bug: 323447554
Test: Boot to home
Change-Id: I5de14147fbe16242182e3940c9318c3dec372bdc
2024-02-06 16:17:32 +00:00
Xin Li
b25ac8c5fa [automerger skipped] Merge Android 24Q1 Release (ab/11220357) am: 3b8ff0887e -s ours
am skip reason: Merged-In I6cf8988e22bbbcac11a8b195f00021c0920f7e6d with SHA-1 fe45ceb4ef is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/25973916

Change-Id: I70eb3413168baab521365b329fc2cae7e0e06012
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2024-01-31 02:02:32 +00:00
Darren Hsu
0ddbc3d4a3 sepolicy: label required display paths for hal_power_stats
Bug: 322458289
Test: dumpsys android.hardware.power.stats.IPowerStats/default
Change-Id: I8dd6d0a26f4dc6dcdd3025f36f8bb5262a7a1a25
Signed-off-by: Darren Hsu <darrenhsu@google.com>
2024-01-26 17:57:06 +08:00
Xin Li
3b8ff0887e Merge Android 24Q1 Release (ab/11220357)
Bug: 319669529
Merged-In: I6cf8988e22bbbcac11a8b195f00021c0920f7e6d
Change-Id: I7b028059ddd64f3abd93f58ef84ec443d10c1d96
2024-01-17 22:12:34 -08:00
Jenny Ho
260dd531fe sepolicy: felix: add wireless path permission
W binder:558_3: type=1400 audit(0.0:734): avc:  denied  { read } for  name="wakeup80" dev="sysfs" ino=86209 scontext=u:r:system_suspend:s0 tcontext=u:object_r:sysfs_batteryinfo:s0 tclass=dir permissive=0
E android.system.suspend-service: Error opening kernel wakelock stats for: wakeup13 (../../devices/platform/10da0000.hsi2c/i2c-8/8-0061/power_supply/wireless/wakeup13): Permission denied

W UeventThread: type=1400 audit(0.0:189): avc:  denied  { read } for  name="voltage_now" dev="sysfs" ino=69837 scontext=u:r:hal_wireless_charger:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=0

Bug: 320193504
Change-Id: Iec4bf714ab4051fcd32bfc8c824e81af0fc35793
Signed-off-by: Jenny Ho <hsiufangho@google.com>
2024-01-16 15:40:32 +08:00
Limon Mia
bb2d2ad0c9 allow bthal to access vendor bluetooth folder
Bug: 316071157
Test: enable vendor btsnoop property and check the vendor snoop log
Flag: EXEMPT .
Change-Id: I5b1b9f475089313c205ae384589e07414497a72b
2023-12-26 08:01:41 +00:00
Xin Li
804c6d80bb [automerger skipped] Merge Android 14 QPR1 am: 14ea4f5b53 -s ours am: acfb9aede4 -s ours am: 66f45c611e -s ours
am skip reason: Merged-In I92b1361b9833dcf97f0eb37ad65b8c85b048d24a with SHA-1 bf9b89a17e is already in history

Original change: https://android-review.googlesource.com/c/device/google/felix-sepolicy/+/2865148

Change-Id: I9150d16e857d16af471272ced5691fb87138c903
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-12-11 22:57:27 +00:00
Xin Li
66f45c611e [automerger skipped] Merge Android 14 QPR1 am: 14ea4f5b53 -s ours am: acfb9aede4 -s ours
am skip reason: Merged-In I92b1361b9833dcf97f0eb37ad65b8c85b048d24a with SHA-1 bf9b89a17e is already in history

Original change: https://android-review.googlesource.com/c/device/google/felix-sepolicy/+/2865148

Change-Id: Ic88a5f604716db65c3428f2f7ed478b4becdd24d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-12-11 22:02:14 +00:00
Xin Li
acfb9aede4 [automerger skipped] Merge Android 14 QPR1 am: 14ea4f5b53 -s ours
am skip reason: Merged-In I92b1361b9833dcf97f0eb37ad65b8c85b048d24a with SHA-1 bf9b89a17e is already in history

Original change: https://android-review.googlesource.com/c/device/google/felix-sepolicy/+/2865148

Change-Id: Id89fa1bea38a28121a56cf25e305a8321c2cd1f2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-12-11 21:16:25 +00:00
Xin Li
14ea4f5b53 Merge Android 14 QPR1
Merged-In: I92b1361b9833dcf97f0eb37ad65b8c85b048d24a
Bug: 315507370
Change-Id: Ic7101f803005df1759f8a3805bce76b8bc5dc75e
2023-12-08 13:13:23 -08:00
Treehugger Robot
c5697205e7 Merge "Update SELinux error" into main 2023-10-20 13:16:59 +00:00
Xin Li
bb4cd66700 [automerger skipped] Merge 10952656 am: bf9b89a17e -s ours am: e8c0aa94ed -s ours
am skip reason: Merged-In Ic35032349ac6c8668a5aca48f95b0b9b09fd4931 with SHA-1 c7f972b65d is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/25089592

Change-Id: I8688ef8e0e8fb04a6279763208b66b5332554e8a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-10-19 23:54:26 +00:00
Xin Li
e8c0aa94ed [automerger skipped] Merge 10952656 am: bf9b89a17e -s ours
am skip reason: Merged-In Ic35032349ac6c8668a5aca48f95b0b9b09fd4931 with SHA-1 c7f972b65d is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/25089592

Change-Id: Ib3fddbac3d6ae12498cd923742a3198969b5e741
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-10-19 18:47:41 +00:00
Wilson Sung
fe45ceb4ef Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 306344097
Test: scanBugreport
Bug: 305600372
Test: scanAvcDeniedLogRightAfterReboot
Bug: 305600372
Change-Id: I6cf8988e22bbbcac11a8b195f00021c0920f7e6d
2023-10-19 11:06:20 +00:00
Xin Li
bf9b89a17e Merge 10952656
Merged-In: Ic35032349ac6c8668a5aca48f95b0b9b09fd4931
Change-Id: I92b1361b9833dcf97f0eb37ad65b8c85b048d24a
2023-10-17 10:06:29 -07:00
Wilson Sung
1cac1ae708 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 305600843
Bug: 305600734
Bug: 305600372
Change-Id: I5c54a0938e80236853048948eeb380c5b1409b9e
2023-10-16 05:39:05 +00:00
Xin Li
9f559d7267 [automerger skipped] Merge Android 14 am: fe44673ea9 -s ours am: 0374df24b8 -s ours am: 91cba67266 -s ours am: 7018e13eb7 -s ours am: c7f972b65d -s ours
am skip reason: Merged-In I48f5d334d01d9031b488a0051c84bf4b38d2b09a with SHA-1 3254e69a85 is already in history

Original change: https://android-review.googlesource.com/c/device/google/felix-sepolicy/+/2775024

Change-Id: Id9ba75a26c90ec768b28443dd8b3620ea9a13878
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-10-07 00:19:37 +00:00
Xin Li
c7f972b65d [automerger skipped] Merge Android 14 am: fe44673ea9 -s ours am: 0374df24b8 -s ours am: 91cba67266 -s ours am: 7018e13eb7 -s ours
am skip reason: Merged-In I48f5d334d01d9031b488a0051c84bf4b38d2b09a with SHA-1 3254e69a85 is already in history

Original change: https://android-review.googlesource.com/c/device/google/felix-sepolicy/+/2775024

Change-Id: Ic35032349ac6c8668a5aca48f95b0b9b09fd4931
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-10-06 11:00:08 +00:00
Xin Li
7018e13eb7 [automerger skipped] Merge Android 14 am: fe44673ea9 -s ours am: 0374df24b8 -s ours am: 91cba67266 -s ours
am skip reason: Merged-In I48f5d334d01d9031b488a0051c84bf4b38d2b09a with SHA-1 3254e69a85 is already in history

Original change: https://android-review.googlesource.com/c/device/google/felix-sepolicy/+/2775024

Change-Id: I750294d8fa2914a8b1eb576dfeb34caee491658e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-10-06 09:50:17 +00:00
Xin Li
91cba67266 [automerger skipped] Merge Android 14 am: fe44673ea9 -s ours am: 0374df24b8 -s ours
am skip reason: Merged-In I48f5d334d01d9031b488a0051c84bf4b38d2b09a with SHA-1 3254e69a85 is already in history

Original change: https://android-review.googlesource.com/c/device/google/felix-sepolicy/+/2775024

Change-Id: I52f4ff3fe8f4ad6186c5a10a2e2e7f15a2ebae9c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-10-06 08:58:36 +00:00
Xin Li
0374df24b8 [automerger skipped] Merge Android 14 am: fe44673ea9 -s ours
am skip reason: Merged-In I48f5d334d01d9031b488a0051c84bf4b38d2b09a with SHA-1 3254e69a85 is already in history

Original change: https://android-review.googlesource.com/c/device/google/felix-sepolicy/+/2775024

Change-Id: I1f785729870ed98a5c1ff782108db73c6fb310e1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-10-06 07:51:36 +00:00
Xin Li
fe44673ea9 Merge Android 14
Bug: 298295554
Merged-In: I48f5d334d01d9031b488a0051c84bf4b38d2b09a
Change-Id: Ib270fe228674c231af8414b0645850d16a38eb3a
2023-10-05 15:33:24 -07:00
Desmond Huang
9a3bd6d75b Relocate common tracking denial entries
Bug: 299029620
Change-Id: If7211101f01ca07ad5ca46991c1acec13ab184c9
2023-09-14 14:12:18 +08:00
Xin Li
94ed609d11 [automerger skipped] Merge Android U (ab/10368041) am: ad837e70f4 -s ours am: 91be16b6c7 -s ours am: e48dad8ad9 -s ours am: ae031adfcf -s ours
am skip reason: Merged-In Ie57b7ae1cdd680523e78d20809aa9b37051a6808 with SHA-1 71e5601787 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/24181615

Change-Id: Ifdd3b9979e0839367fe726e0d7e375ab63ed689e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-29 20:37:34 +00:00
Xin Li
ae031adfcf [automerger skipped] Merge Android U (ab/10368041) am: ad837e70f4 -s ours am: 91be16b6c7 -s ours am: e48dad8ad9 -s ours
am skip reason: Merged-In Ie57b7ae1cdd680523e78d20809aa9b37051a6808 with SHA-1 71e5601787 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/24181615

Change-Id: I3c1ad3f6d5755019556eedbbd4f1ee60f1271523
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-29 01:10:27 +00:00
Xin Li
e48dad8ad9 [automerger skipped] Merge Android U (ab/10368041) am: ad837e70f4 -s ours am: 91be16b6c7 -s ours
am skip reason: Merged-In Ie57b7ae1cdd680523e78d20809aa9b37051a6808 with SHA-1 71e5601787 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/24181615

Change-Id: I37adaa34f7253a6654f8c89d8f26ac2fbe2ebbb6
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-29 00:34:44 +00:00
Xin Li
91be16b6c7 [automerger skipped] Merge Android U (ab/10368041) am: ad837e70f4 -s ours
am skip reason: Merged-In Ie57b7ae1cdd680523e78d20809aa9b37051a6808 with SHA-1 71e5601787 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/24181615

Change-Id: I688424760431023aa9015af103dbb79a2b439938
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-28 23:58:45 +00:00
Xin Li
ad837e70f4 Merge Android U (ab/10368041)
Bug: 291102124
Merged-In: Ie57b7ae1cdd680523e78d20809aa9b37051a6808
Change-Id: I90082f41467d176bab16b9f7df30a383735234cb
2023-08-14 15:33:37 -07:00
eddielan
5990e7698e Correct fps sepolicy error am: 2e9cc3bd53 am: c8b7b50622
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/24353433

Change-Id: Ife157d8d41bc7f7af56813a92e8ef18835bafdf8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-14 11:43:56 +00:00
eddielan
c8b7b50622 Correct fps sepolicy error am: 2e9cc3bd53
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/24353433

Change-Id: I180596e9eec42692da19dc7967e48cfb2246a08b
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-08-14 11:02:05 +00:00
eddielan
2e9cc3bd53 Correct fps sepolicy error
E SELinux : avc:  denied  { find }
name=android.frameworks.sensorservice.ISensorManager/default
scontext=u:r:hal_fingerprint_capacitance:s0
tcontext=u:object_r:fwk_sensor_service:s0
tclass=service_manager permissive=0

Bug: 294959986
Test: make selinux_policy -j128

Change-Id: If7d548c02731864b83e04b97e048cb38b5a8a600
2023-08-08 17:33:06 +08:00
Sebastian Pickl
e8d9e91885 Revert "selinux: fix the wakeup avc denials" am: 959371629b am: c6050bb668 am: 6e6ea34596
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/24189204

Change-Id: I08eb5863d39931ed297045ff7d6ee8ce2dd02866
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-25 12:20:00 +00:00
Sebastian Pickl
6e6ea34596 Revert "selinux: fix the wakeup avc denials" am: 959371629b am: c6050bb668
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/24189204

Change-Id: I71d2a8a0f47b259d5e58ffc571657a5cffeb6203
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-25 11:36:48 +00:00
Sebastian Pickl
c6050bb668 Revert "selinux: fix the wakeup avc denials" am: 959371629b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/24189204

Change-Id: Ic88b1083c931606b01114182ee3346f44695e83d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-25 10:51:47 +00:00
Sebastian Pickl
959371629b Revert "selinux: fix the wakeup avc denials"
This reverts commit 6cd5fef048.

Reason for revert: build break b/292813704

Change-Id: Ib9cb338d2767f62f048c7ae979bc97242d18e500
2023-07-25 08:26:34 +00:00
Ken Yang
c9caf31ee0 selinux: fix the wakeup avc denials am: 6cd5fef048 am: 15b985efa6 am: 68a5d82a54
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/24158114

Change-Id: I7b4aed3c8e9480d363c68aabd4c1f1dab6a7d406
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-25 04:10:43 +00:00
Ken Yang
68a5d82a54 selinux: fix the wakeup avc denials am: 6cd5fef048 am: 15b985efa6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/24158114

Change-Id: Ic0e68446b4fb3211cd4bb8f07ad4707496b8de5d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-25 03:26:22 +00:00
Ken Yang
15b985efa6 selinux: fix the wakeup avc denials am: 6cd5fef048
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/24158114

Change-Id: I82d6423360c14f80a89b498ad9de471b62f105fd
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-07-25 02:41:13 +00:00
Ken Yang
6cd5fef048 selinux: fix the wakeup avc denials
Bug: 292076108
Change-Id: I8ce862cd945edc63541b36cd3e5227c43b4c7caa
Signed-off-by: Ken Yang <yangken@google.com>
2023-07-24 05:43:40 +00:00
DesmondH
4b2e6c4dc4 Remove fixed or obsolete entries
Fix: 275001897
Fix: 277155247
Change-Id: I50f087e1e135c3391055c6955cc1be0f2ddfe6af
2023-06-14 16:48:18 +00:00
changyan
8197f35e99 Remove the tracking_denials entry as the issue
Bug: 282626702
Change-Id: Ieef6b12b7bec17653e82497f3be9fd88f832f488
2023-06-08 06:22:39 +00:00
DesmondH
c49d964214 Remove obsolete entries
Bug: 281602658
Bug: 240632721
Bug: 275001799
Bug: 270633150
Bug: 280706429
Bug: 270247256
Fix: 240632821
Fix: 282626451
Fix: 277155366
Change-Id: I6fd36358d6126b10892d4644945b8293a72731db
2023-06-02 03:21:41 +00:00
Feiyu Chen
51a7568197 Merge "Remove two hal_camera_default errors from tracking_denials/bug_map" 2023-05-30 15:29:16 +00:00
feiyuchen
d792cf8cd5 Remove two hal_camera_default errors from tracking_denials/bug_map
Bug: 275001798
Test: mm
Change-Id: I9168df124aebf272b73c8a40b03fa99a50876352
2023-05-26 15:57:29 +00:00
Ted Wang
80a56e3eb1 Add sepolicy for aidl bt extension hal am: fda887ed1b am: 144cca57fa
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/23367245

Change-Id: Ifc8c7b3558226103859e54ab6aa08fdb26bd289e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-23 07:22:13 +00:00
Ted Wang
144cca57fa Add sepolicy for aidl bt extension hal am: fda887ed1b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/23367245

Change-Id: I2929c5403e5b6e0fc35da9cf719a2bedd1e4ac10
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-23 06:40:53 +00:00
Ted Wang
fda887ed1b Add sepolicy for aidl bt extension hal
Bug: 274906319
Bug: 282685427
Test: make sepolicy and manual test
Change-Id: Ic8f870a570f5bb68277419a6ae6a8350c6c53639
2023-05-22 07:44:40 +00:00
Wilson Sung
65713db080 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 282626451
Test: scanBugreport
Bug: 282626702
Bug: 282626428
Bug: 282626451
Test: scanAvcDeniedLogRightAfterReboot
Bug: 282626451
Change-Id: I0d09420daa5e19b5fa36cda10f3d43b3223fb437
2023-05-15 15:32:29 +08:00