Commit graph

36 commits

Author SHA1 Message Date
Mason Wang
b1d4e8ab2f Allow dumpstate to access touch vendor nodes
Fix following avc denial log:
avc: denied { write } for name="stm_fts_cmd" dev="sysfs" ino=113133 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=1 bug=b/240632721
avc: denied { open } for path="/sys/devices/platform/10950000.spi/spi_master/spi6/spi6.0/stm_fts_cmd" dev="sysfs" ino=113133 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=1 bug=b/240632721
avc: denied { read } for name="stm_fts_cmd" dev="sysfs" ino=113133 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=1 bug=b/240632721
avc: denied { read } for name="driver_test" dev="proc" ino=4026535565 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:proc:s0 tclass=file permissive=0 bug=b/240632721
avc: denied { read } for name="appid" dev="sysfs" ino=108992 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=0 bug=b/240632721


Bug: 226475119
Bug: 254164096
Test: There are no above avc denial logs.
Change-Id: Ie01104ebfb94154584d9d466cb295095eb634f48
2022-10-28 12:44:25 +08:00
TreeHugger Robot
9219b31d13 Merge "sepolicy: remove tracking bugs for PowerStatsHAL and SystemSuspend" into tm-qpr-dev 2022-10-27 03:26:15 +00:00
Darren Hsu
577965ec5f sepolicy: remove tracking bugs for PowerStatsHAL and SystemSuspend
b/240632970 is not reproducible on TD3A.221020.001.
b/240632822 has been fixed by ag/20209545.

Bug: 240632970
Bug: 240632822
Test: Capture bugreport and check no avc denails
Change-Id: I9a2290e2857415c3edecd98b88af6382a42530ff
Signed-off-by: Darren Hsu <darrenhsu@google.com>
2022-10-26 17:31:17 +08:00
eddielan
ef12403d44 Fix FPS servicemanager sepolicy issue
10-25 03:25:07.740   429   429 I auditd  : type=1400 audit(0.0:4):
avc: denied { call } for comm="servicemanager"
scontext=u:r:servicemanager:s0
tcontext=u:r:hal_fingerprint_capacitance:s0
tclass=binder permissive=0

Bug: 253533883
Test: make selinux_policy -j128 && check log on device
Change-Id: Ic3007d53398eb9770466c24b3aa49c1325bdbb47
2022-10-26 12:01:36 +08:00
TreeHugger Robot
f2b9557796 Merge "sepolicy: add sysfs_wakeup labels for System Suspend" into tm-qpr-dev 2022-10-19 09:18:11 +00:00
Darren Hsu
99f9cd6a45 sepolicy: add sysfs_wakeup labels for System Suspend
Bug: 253980198
Test: run vts -m SuspendSepolicyTests
Change-Id: Ie58c35b37ad0a904d0292d2be9092f82b02d514b
Signed-off-by: Darren Hsu <darrenhsu@google.com>
2022-10-18 11:39:51 +08:00
eddielan
2fef9efcc4 Remove fingerprint tracking bug
Patch was merged on ag/19457937

Bug: 240633068
Test: make selinux_policy -j128
Change-Id: Ic25e266701993fadc51b12c25c9a170c38e29785
2022-10-17 15:09:24 +08:00
Ted Lin
5126a011d0 Remove bug mapping in the tracking denials
Bug: 240632860
Test: Check the bugreport
Signed-off-by: Ted Lin <tedlin@google.com>
Change-Id: Ic4c68fe39b3e7e82cf9edcb6b594b598f5ba9499
2022-09-07 16:50:57 +08:00
Adam Shih
454e019bee Update error on ROM 8979803
Bug: 240632860
Test: SELinuxUncheckedDenialBootTest
Change-Id: Ie192b157e89f86fe36b99202e6ab8677a55c7cee
2022-08-25 10:52:53 +08:00
Wasb Liu
2dcb7cc94f Add sepolicy for dual_batt_gauge power supply
08-23 02:45:54.456   860   860 I auditd  : type=1400 audit(0.0:4): avc: denied { read } for comm="android.hardwar" name="type" dev="sysfs" ino=100372 scontext=u:r:hal_health_default:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=0

Bug: 243491187
Test: reboot device and check the avc
Signed-off-by: Wasb Liu <wasbliu@google.com>
Change-Id: I7600c816e743fc91afaf66db00ba332229b21e28
2022-08-24 05:01:15 +00:00
Ted Lin
1ef6c24de8 Merge "Remove bug mapping in the tracking denials" into tm-qpr-dev 2022-08-19 07:36:47 +00:00
TreeHugger Robot
e334d5ec9f Merge "Revert "Update SELinux error"" into tm-qpr-dev 2022-08-09 07:37:37 +00:00
Adam Shih
baebf44224 Revert "Update SELinux error"
This reverts commit 342edcb7de.

Reason for revert: ag/19563471 has fixed the problem

Change-Id: Iad76a9ca182e1cf3363dc58aed943ef4ae13be59
2022-08-09 06:15:39 +00:00
Ted Lin
b1ce1cbeec Remove bug mapping in the tracking denials
Bug: 240632860
Test: Check the bugreport
Signed-off-by: Ted Lin <tedlin@google.com>
Change-Id: I35c69c1289337cd40ab3511512045b986bad9388
2022-08-04 08:50:16 +00:00
Ted Lin
fd1cdb48b7 Sepolicy: fix the avc
07-29 08:18:53.464   876   876 I auditd  : type=1400 audit(0.0:4): avc: denied { read } for comm="android.hardwar" name="type" dev="sysfs" ino=78463 scontext=u:r:hal_health_default:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=0

Bug: 240632860
Test: reboot device and check the avc
Signed-off-by: Ted Lin <tedlin@google.com>
Change-Id: Ibb1f93c2003e9229c1fd2b3bd14ee022fa6539cc
2022-08-03 09:18:35 +00:00
Adam Shih
342edcb7de Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 241034024
Change-Id: I712b025aef59d838773ff55b62b8fb5ecbcbb35b
2022-08-02 10:22:27 +08:00
TreeHugger Robot
bf70ca168c Merge "Fix FPS hwservice sepolicy issue" into tm-qpr-dev 2022-08-01 07:33:53 +00:00
eddielan
99914783af Fix FPS hwservice sepolicy issue
avc:  denied  { find } for interface=com.fingerprints42.extension::IFingerprintEngineering sid=u:r:hal_fingerprint_capacitance:s0 pid=895 scontext=u:r:hal_fingerprint_capacitance:s0 tcontext=u:object_r:default_android_hwservice:s0 tclass=hwservice_manager permissive=0

Bug: 240633068
Test: make selinux_policy -j128
Change-Id: Ifd13d8c73c97cef9a85555a7d09de4424548ca73
2022-07-29 12:15:19 +08:00
Adam Shih
44f363e147 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 240632970
Bug: 240632821
Bug: 240632822
Bug: 240632721
Bug: 240633068
Bug: 240632860
Change-Id: I9b38d4edca95f2721d94c2d7bc1af046cd8382b9
2022-07-29 10:17:52 +08:00
luofrank
f6c212c921 Add rules to allow Sensor HAL write access to als_table
Sensor HAL needs write access to
/sys/class/backlight/panel1-backlight/als_table.

Bug: 238847421
Test: Refer to b/238847421#comment5.
Change-Id: I21845b7772b3806f8796dab7e23b91fe3ae6c881
2022-07-25 09:50:17 +08:00
TreeHugger Robot
fde1b9d375 Merge "add sepolicy for both vibrator path" into tm-qpr-dev 2022-07-22 01:44:54 +00:00
TreeHugger Robot
82d6ccff80 Merge "Add service context for IDisplay/secondary" into tm-qpr-dev 2022-07-21 08:21:39 +00:00
Chase Wu
eb0d700258 add sepolicy for both vibrator path
Change the both driver path's sysfs to sysfs_vibrator

Bug: 181615889
Test: adb shell ls -lZ /sys/bus/i2c/devices/i2c-cs40l26a/default/
Test: adb shell ls -lZ /sys/bus/i2c/devices/i2c-cs40l26a-dual/default/
Signed-off-by: Chase Wu <chasewu@google.com>
Change-Id: I839d4b9406d140a326730873cb8cb86d13188fe2
2022-07-21 16:20:10 +08:00
Adam Shih
eece5dd7a0 Update SELinux error
Bug: 234547283
Change-Id: Ie74f138fdb08167ec4e3ebf2461bc430e6ca3664
2022-07-18 02:58:25 +00:00
Adam Shih
0ee97b98fe setup felix tracking folder
Bug: 234547283
Test: build pass
Change-Id: Ibe8461efae81360fdf18c1908ef9e6b1d080a482
2022-07-15 10:25:44 +08:00
TreeHugger Robot
8f8a358606 Merge "Add sepolicy for Blutooth" into tm-qpr-dev 2022-07-06 07:51:36 +00:00
eddielan
c16dc8d226 fingerprint: Add new lable for capacitance fingerprint
u:object_r:hal_fingerprint_capacitance_exec:s0
android.hardware.biometrics.fingerprint-service.fpc42

Cherry-pick from ag/19085661

Bug: 235424180
Test: make selinux_policy -j128
Test: Check binary sepolicy on device
Change-Id: I8859965df77356b4691292ab66dbbb8c0b9db3b3
2022-07-04 14:23:16 +08:00
Ted Wang
9d19bb92a9 Add sepolicy for Blutooth
Bug: 236681575
Test: Manually
Change-Id: I7bb8af445718703032ba1b22858654b6a5972063
2022-06-28 15:19:42 +08:00
linpeter
96d7d967fe Add service context for IDisplay/secondary
Bug: 210380703
test: check avc
Change-Id: I32a62b5cbbd0168d3a90245af04a204e74d063b2
2022-06-14 21:58:44 +08:00
linpeter
bc7b3c639c Add file context for decon1 and dsim1
Bug: 232886745
test: check sysfs context
Change-Id: Icb85a54fd4d5b949fde698ca7afeb97a0bd43408
2022-06-09 15:47:41 +08:00
Wasb Liu
1b1d98425f Add sepolicy for P9222 WLC power_supply
avc: denied { getattr } for comm="android.hardwar" path="/sys/devices/platform/10da0000.hsi2c/i2c-7/i2c-p9222/power_supply/wireless/capacity" dev="sysfs" ino=72303 scontext=u:r:hal_health_default:s0 tcontext=u:object_r:sysfs:s0 tclass=file permissive=0

Bug: 229820966
Test: build ok, wireless power_supply can be detected by healthd
Signed-off-by: Wasb Liu <wasbliu@google.com>
Change-Id: I3078a11d6398be626d2c419ebee7d9e33babe441
2022-04-29 16:40:45 +08:00
JimiChen
d4c74fffeb Add sepolicy for specific camera components
Bug: 228822580
Bug: 228823145
Test: build okay
Change-Id: I9530292acb28414d13374128d9f453bdb602503f
2022-04-15 15:41:43 +08:00
horngchuang
4f83b87879 Add F10 specific camera component sepolicy settings
Bug: 227709256
Test: build okay
Change-Id: If1d2a22a0d3efd5b87a44f137ad115091e5653ac
2022-04-08 19:06:35 +08:00
Joel Galenson
93f622093c Include core policy OWNERS
Test: None
Change-Id: I79aa7e4f49da1d0c64ccf808f5fddac6bead73d0
2021-12-21 07:40:09 -08:00
Cyan_Hsieh
a61abb8263 Initial device felix sepolicy
Bug: 206057564
Change-Id: Ie0a08bf9c7a6cdaf634efce69401bcaa9e6a5d1b
2021-12-06 12:12:10 +08:00
Roman Yepishev
7fe887b3f5 Initial empty repository 2021-11-22 17:46:22 +00:00