Commit graph

134 commits

Author SHA1 Message Date
Wilson Sung
917adb5d83 Update error on ROM 9890454 am: 60404f62e3 am: dcad76e0d9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/22525744

Change-Id: Ieaae884ff84ae2fa4c3ef8beeff0a076c4d68b86
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-07 08:41:53 +00:00
Wilson Sung
dcad76e0d9 Update error on ROM 9890454 am: 60404f62e3
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/22525744

Change-Id: I5ece6adea9383fd304c0d05e8e84da23ac5c52ac
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-07 08:00:29 +00:00
Wilson Sung
60404f62e3 Update error on ROM 9890454
Bug: 277155247
Bug: 277155366
Test: pts-tradefed run pts -m PtsSELinuxTest
Change-Id: I4de26053ca9b4e572a62a40d73268453cee3b7a1
2023-04-07 06:37:02 +00:00
Wilson Sung
e529e8dbcf Update SELinux error am: cb0c1bab29 am: 700a5ee970
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/22244822

Change-Id: Id3d24d04373aea241c3379c456e0037d8db42954
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-24 06:06:27 +00:00
Wilson Sung
1adb4435e3 Update SELinux error am: cb0c1bab29 am: ef2ecb700d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/22244822

Change-Id: I6494465db189f85a6ef4b205e8bb5defd4cb13cf
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-24 06:06:14 +00:00
Wilson Sung
700a5ee970 Update SELinux error am: cb0c1bab29
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/22244822

Change-Id: I1f46af13a9869f021d45c1b6544eed146010916f
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-24 05:39:27 +00:00
Wilson Sung
ef2ecb700d Update SELinux error am: cb0c1bab29
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/22244822

Change-Id: Icc207b2b92aaa55c5a7bcccc584ec8420e6fa9ce
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-03-24 05:39:10 +00:00
Wilson Sung
cb0c1bab29 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 275001798
Test: scanBugreport
Bug: 275001897
Bug: 275001799
Change-Id: Ifa1adaaa2bf33297e3c36a559dccc12726568896
2023-03-24 11:11:05 +08:00
sukiliu
4672405091 Update SELinux error am: 036e3370c2 am: d60c246e2b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/21572470

Change-Id: I714cb37473d22f4ea001f7cd5d15249fe6634ef8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-24 06:55:32 +00:00
sukiliu
d60c246e2b Update SELinux error am: 036e3370c2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/21572470

Change-Id: I9f56bb0bf55d95cdce3a24e0c31376ecc1bff808
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-24 06:17:41 +00:00
sukiliu
c39c2c93d1 Update SELinux error am: 036e3370c2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/21572470

Change-Id: I791473498a5b703b7852538e8219b51f82afbbd2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-24 04:26:28 +00:00
sukiliu
036e3370c2 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 270633150
Change-Id: I9dc73b7e5be8d872d4c68972df77907e08b656f3
2023-02-24 09:59:43 +08:00
leochuang
c1ce4499e3 Update SELinux error am: 88988e5d2e am: abb924f3df
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/21533864

Change-Id: Idcebb3e79c195536b8492fe0a5957437ef1593a4
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-23 03:23:03 +00:00
leochuang
abb924f3df Update SELinux error am: 88988e5d2e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/21533864

Change-Id: I231c08713d77f9c9b38f181534aa0d0e2613b0d9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-23 01:30:09 +00:00
leochuang
14491e4803 Update SELinux error am: 88988e5d2e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/21533864

Change-Id: I315f53f05496d4d586ce6c3f19d1456301a31b57
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-02-23 01:29:55 +00:00
leochuang
88988e5d2e Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 270247256
Change-Id: Id8a692a7e5bc3979c000b85de60785216b8f6a64
2023-02-22 10:29:31 +08:00
Ken Yang
698f1f3488 Merge "WLC: Cleanup the sysfs_wlc policies" 2023-01-13 14:41:32 +00:00
Joshua McCloskey
451bd3388d [automerger skipped] Allow SystemUI to access fp hal. am: 663979a772 am: d335b77a09 -s ours
am skip reason: Merged-In Iefeca78703af30246420a55133c00769b84789f9 with SHA-1 e71f3a8739 is already in history

Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/20922424

Change-Id: I186d35f68be30a22c4a7310a973404746c5f3bf5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-01-11 04:30:31 +00:00
Joshua McCloskey
d335b77a09 Allow SystemUI to access fp hal. am: 663979a772
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/20922424

Change-Id: I0b77b7218028fc0566f82ecc8d9c70fd66a8ac6c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-01-11 04:05:05 +00:00
Joshua McCloskey
663979a772 Allow SystemUI to access fp hal.
Bug: 261209932
Test: Verified SystemUI can access HAL extension.
Change-Id: Iefeca78703af30246420a55133c00769b84789f9
Merged-In: Iefeca78703af30246420a55133c00769b84789f9
2023-01-10 01:39:36 +00:00
Joshua Mccloskey
fd408fc003 Merge "Allow SystemUI to access fp hal." 2023-01-10 01:38:27 +00:00
Joshua McCloskey
e71f3a8739 Allow SystemUI to access fp hal.
Bug: 261209932
Test: Verified SystemUI can access HAL extension.
Change-Id: Iefeca78703af30246420a55133c00769b84789f9
2023-01-09 18:00:07 +00:00
Eddie Lan
c6adebd32f Merge "fingerprint: allow fps to access sysfs_leds" into tm-qpr-dev am: c3b8cda0f5 am: 884f7fb41d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/20619011

Change-Id: I4f7d7e2ca2fb0f00899fd6766813f6341f7f1283
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-01-09 13:14:59 +00:00
Eddie Lan
884f7fb41d Merge "fingerprint: allow fps to access sysfs_leds" into tm-qpr-dev am: c3b8cda0f5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/20619011

Change-Id: I141ec0a89718917b3a1125b0c319ef5f3ee699a8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-01-09 12:38:11 +00:00
Eddie Lan
c3b8cda0f5 Merge "fingerprint: allow fps to access sysfs_leds" into tm-qpr-dev 2023-01-09 12:06:39 +00:00
Ken Yang
b6e7c3d0c7 WLC: Cleanup the sysfs_wlc policies
Bug: 263830018
Change-Id: I534eda445241e3a907b11004cafb737f6ec63586
Signed-off-by: Ken Yang <yangken@google.com>
2023-01-06 19:24:38 +00:00
Wasb Liu
d6606b7439 sepolicy: add necessary sepolicy for dual battery am: 49cdfcb3c7 am: 6c46e922ab
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/20803963

Change-Id: I99ec363f789026842ff58ba39801f479ac41cf18
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-27 08:53:31 +00:00
Wasb Liu
6c46e922ab sepolicy: add necessary sepolicy for dual battery am: 49cdfcb3c7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/20803963

Change-Id: I6f13e1edb662003b8ab907e0be8740aeed4d8fe9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-27 08:17:26 +00:00
Wasb Liu
49cdfcb3c7 sepolicy: add necessary sepolicy for dual battery
12-22 16:24:51.964  1000   865   865 I auditd  : type=1400 audit(0.0:10): avc: denied { read } for comm="android.hardwar" name="logbuffer_maxfg_secondary" dev="tmpfs" ino=799 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:device:s0 tclass=chr_file permissive=0
12-22 16:24:51.968  1000   865   865 I auditd  : type=1400 audit(0.0:11): avc: denied { read } for comm="android.hardwar" name="logbuffer_maxfg_secondary_monitor" dev="tmpfs" ino=630 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:device:s0 tclass=chr_file permissive=0
12-22 16:24:51.968  1000   865   865 I auditd  : type=1400 audit(0.0:12): avc: denied { read } for comm="android.hardwar" name="logbuffer_dual_batt" dev="tmpfs" ino=1040 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:device:s0 tclass=chr_file permissive=0

12-22 16:23:17.056  1000   522   522 I auditd  : type=1400 audit(0.0:4): avc: denied { read } for comm="binder:522_1" name="wakeup65" dev="sysfs" ino=79686 scontext=u:r:system_suspend:s0 tcontext=u:object_r:sysfs_batteryinfo:s0 tclass=dir permissive=0

Bug: 263496320
Test: no dual batt related denied
Change-Id: I021cd15d771524828a942fe1e4c63e3a24418ae8
Signed-off-by: Wasb Liu <wasbliu@google.com>
2022-12-23 09:21:05 +00:00
Ken Yang
7cea766957 Merge "WLC: Add device specific sepolicy for wireless_charger" 2022-12-21 08:36:16 +00:00
Ken Yang
97c1d104cc WLC: Add device specific sepolicy for wireless_charger
Bug: 237600973
Change-Id: I301c636cffb5520aa7bcf998d099c29ca19a2dd6
Signed-off-by: Ken Yang <yangken@google.com>
2022-12-20 00:58:11 +00:00
Jenny Ho
05a2ff9ae0 remove tracking denial of device chr_file am: 3a92d3d265 am: edce76c2b1
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/20733206

Change-Id: I93103c93ffe596a8bdd076dc5b281f889060909d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-16 08:04:34 +00:00
Jenny Ho
edce76c2b1 remove tracking denial of device chr_file am: 3a92d3d265
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/20733206

Change-Id: I51af87a6a17323a334cf3408e5dd324a097b5571
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-16 07:26:40 +00:00
eddielan
0e76ae19c1 fingerprint: allow fps to access sysfs_leds
Bug: 261151317
Test: make selinux_policy -j112
Change-Id: If098515510ac48efb7d2ea23f4aeee87869e01e6
2022-12-15 20:53:11 +08:00
Jenny Ho
3a92d3d265 remove tracking denial of device chr_file
Bug: 254164096
Change-Id: I300d092df3610f29f05ca65a89eba5459ca0063a
Signed-off-by: Jenny Ho <hsiufangho@google.com>
2022-12-14 15:21:50 +08:00
Chase Wu
f4be42ae00 Remove sepolicy for vibrator manager service am: c02424796d am: cbfaaeea39
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/20610806

Change-Id: If5c216b5bbcbfda16712a8e8421c0498a35b0900
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-13 11:26:50 +00:00
Chase Wu
cbfaaeea39 Remove sepolicy for vibrator manager service am: c02424796d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/20610806

Change-Id: I558a8250352ec221945eafaaa5f1054488d94ea5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-12-13 10:52:38 +00:00
Chase Wu
c02424796d Remove sepolicy for vibrator manager service
Bug: 260090235
Test: check avc error
Change-Id: I2cb9f9efe849ae6e7fb9b1b5aba2f92a3346af6d
Signed-off-by: Chase Wu <chasewu@google.com>
2022-12-02 01:09:45 +08:00
Mason Wang
6b826a850d [automerger skipped] Allow dumpstate to access touch vendor nodes[DO NOT MERGE] am: 3c82f575b9 am: 7184709e5f -s ours
am skip reason: subject contains skip directive

Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/20541991

Change-Id: I5b92d44c11fc348616bee7fc2384dcb49d99d833
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-11-28 02:21:52 +00:00
Mason Wang
7184709e5f Allow dumpstate to access touch vendor nodes[DO NOT MERGE] am: 3c82f575b9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/20541991

Change-Id: I0b3d46eab39ba1471b751cdd2810fa0cf27fe723
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-11-28 01:53:24 +00:00
Mason Wang
3c82f575b9 Allow dumpstate to access touch vendor nodes[DO NOT MERGE]
Fix following avc denial log:
avc: denied { read } for name="driver_test" dev="proc" ino=4026535583 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:proc:s0 tclass=file permissive=1 bug=b/240632721
avc: denied { write } for name="driver_test" dev="proc" ino=4026535583 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:proc:s0 tclass=file permissive=1 bug=b/240632721
avc: denied { open } for path="/proc/fts/driver_test" dev="proc" ino=4026535583 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:proc:s0 tclass=file permissive=1 bug=b/240632721
avc: denied { open } for path="/sys/devices/platform/10950000.spi/spi_master/spi6/spi6.0/appid" dev="sysfs" ino=110523 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=1 bug=b/240632721
avc: denied { open } for path="/sys/devices/platform/10950000.spi/spi_master/spi6/spi6.0/stm_fts_cmd" dev="sysfs" ino=110529 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=1 bug=b/240632721
avc: denied { open } for path="/proc/fts_ext/driver_test" dev="proc" ino=4026535585 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:proc:s0 tclass=file permissive=1 bug=b/240632721
avc: denied { write } for name="stm_fts_cmd" dev="sysfs" ino=113133 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=1 bug=b/240632721
avc: denied { read } for name="stm_fts_cmd" dev="sysfs" ino=113133 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=1 bug=b/240632721
avc: denied { read } for name="appid" dev="sysfs" ino=108992 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=0 bug=b/240632721


Bug: 226475119
Bug: 254164096
Test: There are no above avc denial logs.
Change-Id: I0a136a7e259640e3e13ea66c945251cf26878b33
2022-11-24 15:35:16 +08:00
Nicole Lee
50e095c30d Revert "Allow dumpstate to access touch vendor nodes" am: d6fe8df131 am: bb99a93833
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/20519118

Change-Id: I92b3ab14af65c34621046e42dac72e091c59dda1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-11-22 07:22:33 +00:00
Nicole Lee
bb99a93833 Revert "Allow dumpstate to access touch vendor nodes" am: d6fe8df131
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/20519118

Change-Id: I054a4a0ae0d8136e50be58276ff860294096ba7e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-11-22 06:47:10 +00:00
Nicole Lee
d6fe8df131 Revert "Allow dumpstate to access touch vendor nodes"
This reverts commit b1d4e8ab2f.

Reason for revert: DroidMonitor: Potential culprit for Bug 260019672 - verifying through ABTD before revert submission. This is part of the standard investigation process, and does not mean your CL will be reverted.

Change-Id: I8c3bf9982eb9c163e73e75624fd3265ddaa1de95
2022-11-22 06:02:47 +00:00
eddielan
7fd47dc7fb sepolicy: Allow fingerprint to access fwk hwservice am: f544a5a651 am: 25e250aad0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/20441648

Change-Id: I60f5ed42cc20df7c62f0212b68f4a4d0137985b5
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-11-17 04:24:06 +00:00
eddielan
25e250aad0 sepolicy: Allow fingerprint to access fwk hwservice am: f544a5a651
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/20441648

Change-Id: I477e36aeecb337216b8bdbe656370885a2699733
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-11-17 03:29:38 +00:00
eddielan
f544a5a651 sepolicy: Allow fingerprint to access fwk hwservice
11-11 19:57:30.203   464   464 E SELinux : avc:
denied  { find } for interface=android.frameworks.sensorservice::ISensorManager
sid=u:r:hal_fingerprint_capacitance:s0 pid=903
scontext=u:r:hal_fingerprint_capacitance:s0
tcontext=u:object_r:fwk_sensor_hwservice:s0
tclass=hwservice_manager permissive=0

Bug: 258783592
Test: Build pass
Change-Id: I58a31c04cbb45ab12b0bf42a10c57ddf4f065ee7
2022-11-11 20:10:20 +08:00
Chase Wu
6fb0d40d35 add sepolicy for vibrator manager service am: 6c42229dcc am: a8a51be9ae
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/18350088

Change-Id: I3f1a2b791dabc0c323e89b9a763be0ff7bc12b03
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-11-03 10:10:10 +00:00
Chase Wu
a8a51be9ae add sepolicy for vibrator manager service am: 6c42229dcc
Original change: https://googleplex-android-review.googlesource.com/c/device/google/felix-sepolicy/+/18350088

Change-Id: Ib7de5bab2bda145de85e42607c0fdf32862c5431
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2022-11-03 08:08:46 +00:00
Chase Wu
6c42229dcc add sepolicy for vibrator manager service
Bug: 181615889
Test: Run all test suites
Signed-off-by: chasewu <chasewu@google.com>
Change-Id: Ie9e3c86b01afb26557ae69ead813dd123b4df91b
2022-11-03 12:14:03 +08:00