Adam Shih
02f93b6096
modulize hal_neuralnetwork_armnn
...
Bug: 189895314
Bug: 171160755
Bug: 171670122
Bug: 180858476
Test: make sure all affected devices' armnn module has the right label
Change-Id: I6ca736f156497738167ba5eea5606a0e654611b9
2021-06-08 11:17:22 +08:00
Adam Shih
c8b02fc4c3
Remove obsolete context
...
Bug: 190330778
Test: make selinux_policy with such entry gone
Change-Id: I28844c361a951de35d509ce042e64e090188e755
2021-06-08 11:17:17 +08:00
TreeHugger Robot
17b8f5cd4e
Merge "Remove unnecessary rules for vendor rcs app" into sc-dev
2021-06-07 19:01:45 +00:00
Long Ling
5afbe4584f
Merge "sepolicy: gs101: display: fix dumpstate of displaycolor" into sc-dev
2021-06-07 16:36:32 +00:00
Long Ling
1064df0f26
sepolicy: gs101: display: fix dumpstate of displaycolor
...
displaycolor service runs in HW Composer. This change allow displaycolor
to output to dumpstate via pipe fd.
Bug: 189846843
Test: adb bugreport and check displaycolor dump in dumpstate_board.txt
Change-Id: I109db9374124caf9053a9fd7ba6159f83c372038
2021-06-06 22:20:19 -07:00
SalmaxChang
7865bf8577
cbd: Fix avc error
...
avc: denied { search } for comm="cbd" name="/" dev="sda1" ino=2 scontext=u:r:cbd:s0 tcontext=u:object_r:persist_file:s0 tclass=dir permissive=0
Bug: 180687795
Change-Id: I149163760fa47378d03dc2d8c8a00c590788796c
2021-06-07 01:40:59 +00:00
Rick Yiu
f275064208
Merge "gs101-sepolicy: Fix avc denials for sysfs_vendor_sched" into sc-dev
2021-06-07 00:38:36 +00:00
TreeHugger Robot
77cbbc1237
Merge "Add CccDkTimeSyncService" into sc-dev
2021-06-04 21:23:24 +00:00
Hui Wang
724ea61092
Remove unnecessary rules for vendor rcs app
...
Bug: 190194610
Test: make, manual
Change-Id: I99f624a70a36ad6cf47806faf0eed693383dac5f
2021-06-04 14:03:31 -07:00
TreeHugger Robot
aa7a8405e2
Merge "whitechapel: make vframe-secure a system heap" into sc-dev
2021-06-04 18:02:34 +00:00
Sean Callanan
77432c5015
whitechapel: make vframe-secure a system heap
...
The GPU driver uses vframe-secure for secure allocations, so the
corresponding DMA heap file should be visible to all processes so
use the dmabuf_system_secure_heap_device type instead.
In order for this type to be used, we need to ensure that the HAL
Allocator has access to it, so update hal_graphics_allocator_default.te
Finally, since there are no longer any buffer types associated with the
vframe_heap_device type, remove it.
Bug: 182090311
Test: run cts-dev -m CtsDeqpTestCases --module-arg CtsDeqpTestCases:include-filter:dEQP-VK.protected_memory.stack.stacksize_64 and ensure secure allocations succeed
Test: Play DRM-protected video in ExoPlayer and ensure videos render correctly via MFC->DPU.
Change-Id: Id341e52322a438974d4634a4274a7be2ddb4c9fe
2021-06-04 18:01:34 +00:00
TreeHugger Robot
29a5be5603
Merge "storage: update sepolicy for hardwareinfoservice" into sc-dev
2021-06-04 10:45:34 +00:00
TreeHugger Robot
be1f56dba1
Merge "[RCS] Add sepolicy for RCS as non-system app" into sc-dev
2021-06-04 06:22:03 +00:00
Maciej Żenczykowski
729e8901ab
allow hal_usb_impl configfs:dir { create rmdir };
...
This is needed to allow USB HAL to create multi-config gadget
(ie. rndis + ncm).
Bug: 172793258
Test: built and booted on oriole
Signed-off-by: Maciej Żenczykowski <maze@google.com>
Change-Id: Ifb98b23138122ad4e0aeea8dd9c93d7b3e16d3aa
2021-06-04 02:53:11 +00:00
jznpark
3d127f9224
[RCS] Add sepolicy for RCS as non-system app
...
As shannon-rcs has been changed from system app
to non-system app, sepolicy has to be updated.
Bug: 186135775
Bug: 189707387
Test: sanity test
Signed-off-by: jznpark <jzn.park@samsung.com>
Change-Id: I32cce90611c619494136a6b1d01b3fb48330d169
2021-06-03 13:30:26 -07:00
Rick Yiu
a4dbe2ef40
gs101-sepolicy: Fix avc denials for sysfs_vendor_sched
...
Bug: 190011861
Bug: 190011862
Bug: 190011863
Bug: 190012301
Bug: 190012320
Test: boot to home
Change-Id: Icddb42fb194547211e33cf1d871e839a954b0919
2021-06-03 17:55:17 +08:00
Chiawei Wang
9cfc661bee
Merge "pixelstats: fix permission errors" into sc-dev
2021-06-03 08:45:12 +00:00
Chiawei Wang
9d5830ac19
pixelstats: fix permission errors
...
1. sysfs_dma_heap erros are fixed by ag/13926718
2. debugfs_mgm error is fixed by ag/14683912
Bug: 188114896
Bug: 183338421
Bug: 188495492
Test: pts-tradefed run pts -m PtsSELinuxTest
http://sponge2/6cbd0af0-5414-4f2c-aea0-99b4981360a4
Signed-off-by: Chiawei Wang <chiaweiwang@google.com>
Change-Id: Icd2fa4e7f168d15fd4cec3000bc0e7a33eab4d3e
2021-06-03 02:52:33 +00:00
Rick Yiu
b530a26f1f
Merge "gs101-sepolicy: Refine policy for sysfs_vendor_sched" into sc-dev
2021-06-03 00:56:00 +00:00
Peter Csaszar
7ea6a44719
pixel-selinux: Add mlstrustedobject for SJTAG
...
This CL adds the "mlstrustedobject" to types for files involved in the
SJTAG authentication flow, in order to address MLS-based AVC denials.
Bug: 189466122
Test: No more AVC denials when activating SJTAG in BetterBug
Signed-off-by: Peter Csaszar <pcsaszar@google.com>
Change-Id: Ieb88653830ce95751eee5cf26c26fd6302067bce
2021-06-02 12:23:01 -07:00
Rick Yiu
9e8bd699e9
gs101-sepolicy: Refine policy for sysfs_vendor_sched
...
Chagne it to directory based.
Bug: 182509410
Test: device boot normally
Change-Id: I1cfaa95cf07e1e829e747eb99ed39ab64d3ddac1
2021-06-02 04:52:45 +00:00
Aaron Ding
9f8d552411
pixel-selinux: add SJTAG policies
...
This reverts commit b078284e5d
.
Bug: 184768605
Change-Id: Ib0080e2ba3edf7fa654155fb4a7403d52ad2494a
2021-06-02 10:25:51 +08:00
Aaron Ding
2dbe515943
remove sysfs_type from vendor_page_pinner_debugfs
...
Bug: 186500818
Change-Id: If97126a3d46d96342faf89b9698218b6a480a84b
2021-06-01 17:38:28 +08:00
Aaron Ding
b078284e5d
Revert "pixel-selinux: add SJTAG policies"
...
This reverts commit bc525e1a49
.
Bug: 186500818
Change-Id: I0bab67d42530270a819598ac320a5946e5d7aa6d
Signed-off-by: Aaron Ding <aaronding@google.com>
2021-06-01 01:21:14 +08:00
Vova Sharaienko
ce4002966a
Merge "hal_health_default: updated sepolicy" into sc-dev
2021-05-28 17:42:45 +00:00
Rick Yiu
6c5779d0af
Merge "gs101-sepolicy: Allow dumping vendor groups values" into sc-dev
2021-05-28 01:16:34 +00:00
Vova Sharaienko
144b6b06b3
hal_health_default: updated sepolicy
...
This allows the android.hardware.health service to access
AIDL Stats service
Bug: 186578402
Test: Build, flash, boot & and logcat | grep "avc"
Change-Id: I1bfd8dbca4a8a87387c5fc0cc47b9f09a6d07ea4
2021-05-27 01:51:21 +00:00
Harpreet Eli Sangha
e952c414ec
Add CccDkTimeSyncService
...
Bug: 183676280
Test: Build and run example client.
Signed-off-by: Harpreet Eli Sangha <eliptus@google.com>
Change-Id: I862d5f3e8be3cf7d23489be374fabf26e29e0ca5
2021-05-26 16:59:51 +00:00
TreeHugger Robot
9e9c6a75da
Merge "Add sepolicy for Trusty keymint" into sc-dev
2021-05-26 13:23:20 +00:00
sukiliu
073a0f5ed1
Update avc error on ROM 7395282
...
avc: denied { dac_override } for comm="rebalance_inter" capability=1 scontext=u:r:rebalance_interrupts_vendor:s0 tcontext=u:r:rebalance_interrupts_vendor:s0 tclass=capability permissive=0
Bug: 189275648
Test: PtsSELinuxTestCases
Change-Id: I637f1fcd901b8bf59096ba83c927b4d353f0405b
2021-05-26 11:11:03 +08:00
Shawn Willden
c5fdb59287
Add sepolicy for Trusty keymint
...
Bug: 177729159
Test: VtsAidlKeyMintTargetTest on P21
Change-Id: I993faa2a829d3ad4f1b920ff59ba4fd5ef8e7db7
2021-05-25 16:37:29 -06:00
TreeHugger Robot
477e19f032
Merge "Allow mediacodec to access the vframe-secure DMA-BUF heap" into sc-dev
2021-05-25 18:45:37 +00:00
TreeHugger Robot
57eefb5b13
Merge "dumpstate: add sepolicy for hal_dumpstate to access sysfs_display" into sc-dev
2021-05-25 10:12:38 +00:00
Ocean Chen
b8aebc85e1
storage: update sepolicy for hardwareinfoservice
...
avc: denied { search } for name="0:0:0:0" dev="sysfs" ino=57525 scontext=u:r:hardware_info_app:s0:c512,c768 avc: denied { search } for name="health_descriptor" dev="sysfs" ino=57017 scontext=u:r:hardware_info_app:s0:c512,c768 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=dir permissive=0 app=com.google.android.hardwareinfo
avc: denied { search } for name="health_descriptor" dev="sysfs" ino=57017 scontext=u:r:hardware_info_app:s0:c512,c768 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=dir permissive=0 app=com.google.android.hardwareinfo
avc: denied { read } for name="vpd_pg80" dev="sysfs" ino=57559 scontext=u:r:hardware_info_app:s0:c512,c768 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=file permissive=0 app=com.google.android.hardwareinfo
avc: denied { read } for name="model" dev="sysfs" ino=57534 scontext=u:r:hardware_info_app:s0:c512,c768 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=file permissive=0 app=com.google.android.hardwareinfo
avc: denied { read } for name="vendor" dev="sysfs" ino=57533 scontext=u:r:hardware_info_app:s0:c512,c768 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=file permissive=0 app=com.google.android.hardwareinfo
avc: denied { read } for name="rev" dev="sysfs" ino=57535 scontext=u:r:hardware_info_app:s0:c512,c768 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=file permissive=0 app=com.google.android.hardwareinfo
avc: denied { read } for name="eol_info" dev="sysfs" ino=57020 scontext=u:r:hardware_info_app:s0:c512,c768 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=file permissive=0 app=com.google.android.hardwareinfo
avc: denied { read } for name="life_time_estimation_a" dev="sysfs" ino=57021 scontext=u:r:hardware_info_app:s0:c512,c768 tcontext=u:object_r:sysfs_scsi_devices_0000:s0 tclass=file permissive=0 app=com.google.android.hardwareinfo
Bug: 188755652
Test: reboot then check hardwareinfo and avc denined log
Change-Id: Ia03ebdd6b0b46b4c9ace5fbf1fc47a455a55abcb
2021-05-25 16:57:20 +08:00
Roger Fang
56cbfd5a0a
Merge "sepolicy: gs101: add permission for the hardware info dsp part number" into sc-dev
2021-05-25 01:02:39 +00:00
Vinay Kalia
68849437bd
Allow mediacodec to access the vframe-secure DMA-BUF heap
...
This patch fixes the following denial:
HwBinder:751_2: type=1400 audit(0.0:9): avc: denied { open } for
path="/dev/dma_heap/vframe-secure" dev="tmpfs" ino=734
scontext=u:r:mediacodec:s0 tcontext=u:object_r:vframe_heap_device:s0
tclass=chr_file permissive=0
Bug: 188121584
Test: AV1 secure video playback
Signed-off-by: Vinay Kalia <vinaykalia@google.com>
Change-Id: I455b39914dd4316a427f5f756b4fb94a2c4db204
2021-05-24 23:57:28 +00:00
Ines Ayara
dfb3783187
Merge "Transition to using libedgetpu_util.so instead of libedgetpu_darwinn2.so. bug: b/182303547" into sc-dev
2021-05-24 23:55:32 +00:00
Roger Fang
a97bfcc1e1
sepolicy: gs101: add permission for the hardware info dsp part number
...
Bug: 188757638
Test: Manually test passed
Signed-off-by: Roger Fang <rogerfang@google.com>
Change-Id: Id0c3226411b058b613b92e67174f14e64c6c3a2b
2021-05-24 08:16:34 +00:00
Rick Yiu
5aeb1b9e45
gs101-sepolicy: Allow dumping vendor groups values
...
Fix:
avc: denied { read } for name="vendor_sched" dev="sysfs" ino=45566 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:sysfs:s0 tclass=dir permissive=0
avc: denied { read } for name="dump_task_group_ta" dev="proc" ino=4026532542 scontext=u:r:hal_dumpstate_default:s0 tcontext=u:object_r:proc:s0 tclass=file permissive=0
Bug: 172112042
Test: dump data as expected
Change-Id: I9945953dba4afddd34c1535c12193b1f00fdcef9
2021-05-22 21:30:47 +08:00
Grace Chen
16a38b2b6c
Merge "Add selinux permissions for NFC/eSIM firmware upgrade and recovery" into sc-dev
2021-05-21 19:10:52 +00:00
TreeHugger Robot
b42a03fa9e
Merge "Grant sepolicy for Bluetooth Ccc Timesync feature" into sc-dev
2021-05-21 06:41:20 +00:00
SHUCHI LILU
5128ec7db7
Merge "Update avc error on ROM 7380236" into sc-dev
2021-05-21 02:08:56 +00:00
TreeHugger Robot
73b7ad4a3c
Merge "pixel-selinux: add SJTAG policies" into sc-dev
2021-05-21 00:49:42 +00:00
Maurice Lam
32848785da
Merge "DO NOT MERGE. Revert Exo selinux policies for S" into sc-dev
2021-05-20 17:31:08 +00:00
George Lee
3561520ae2
Merge "power: mod sysfs_bcl path" into sc-dev
2021-05-20 15:12:44 +00:00
Ken Huang
560d12c3f1
dumpstate: add sepolicy for hal_dumpstate to access sysfs_display
...
Allow dumpstate to read panel extra info.
Bug: 183061481
Test: adb bugreport
Change-Id: I1902f28c2edceeb5b74ce655f83c8aea7c60825b
2021-05-20 13:53:39 +00:00
sukiliu
ba92629794
Update avc error on ROM 7380236
...
Bug: 188752787
Bug: 188752940
Test: PtsSELinuxTestCases
Change-Id: I5b674d4696ef470956301388f3d0fcc4883010c6
2021-05-20 16:52:43 +08:00
Peter Csaszar
8fd76cee44
pixel-selinux: add SJTAG policies
...
These are the SELinux policies for the sysfs files of the SJTAG
kernel interface. The files are in the following directories:
/sys/devices/platform/sjtag_ap/interface/
/sys/devices/platform/sjtag_gsa/interface/
Bug: 184768605
Signed-off-by: Peter Csaszar <pcsaszar@google.com>
Change-Id: I4ecf5cec5bbd08a44d7dbf88de5f3bc58b6c4fe5
2021-05-20 00:00:30 -07:00
George Lee
f7a9784254
power: mod sysfs_bcl path
...
Recent change in kernel prompted path change.
Bug: 186879633
Test: adb bugreport
dumpstate_board.txt shows:
------ Mitigation Stats (/vendor/bin/sh -c echo "Source\t\tCount\tSOC\tTime\tVoltage"; for f in `ls /sys/devices/virtual/pmic/mitigation/last_triggered_count/*` ; do count=`cat $f`; a=${f/\/sys\/devices\/virtual\/pmic\/mitigation\/last_triggered_count\//}; b=${f/last_triggered_count/last_triggered_capacity}; c=${f/last_triggered_count/last_triggered_timestamp/}; d=${f/last_triggered_count/last_triggered_voltage/}; cnt=`cat $f`; cap=`cat ${b/count/cap}`; ti=`cat ${c/count/time}`; volt=`cat ${d/count/volt}`; echo "${a/_count/} \t$cnt\t$cap\t$ti\t$volt" ; done) ------
Source Count SOC Time Voltage
batoilo 0 0 0 0
ocp_cpu1 0 0 0 0
ocp_cpu2 0 0 0 0
ocp_gpu 0 0 0 0
ocp_tpu 0 0 0 0
smpl_warn 0 0 0 0
soft_ocp_cpu1 0 0 0 0
soft_ocp_cpu2 0 0 0 0
soft_ocp_gpu 0 0 0 0
soft_ocp_tpu 0 0 0 0
vdroop1 0 0 0 0
vdroop2 0 0 0 0
------ Clock Divider Ratio (/vendor/bin/sh -c echo "Source\t\tRatio"; for f in `ls /sys/devices/virtual/pmic/mitigation/clock_ratio/*` ; do ratio=`cat $f`; a=${f/\/sys\/devices\/virtual\/pmic\/mitigation\/clock_ratio\//}; echo "${a/_ratio/} \t$ratio" ; done) ------
Source Ratio
cpu0_clk 0xf041c3
cpu1_heavy_clk 0xf041c3
cpu1_light_clk 0xf041c5
cpu2_heavy_clk 0xf041c3
cpu2_light_clk 0xf041c5
gpu_heavy_clk off
gpu_light_clk off
tpu_heavy_clk off
tpu_light_clk off
------ Clock Stats (/vendor/bin/sh -c echo "Source\t\tStats"; for f in `ls /sys/devices/virtual/pmic/mitigation/clock_stats/*` ; do stats=`cat $f`; a=${f/\/sys\/devices\/virtual\/pmic\/mitigation\/clock_stats\//}; echo "${a/_stats/} \t$stats" ; done) ------
Source Stats
cpu0_clk 0x101
cpu1_clk 0x101
cpu2_clk 0x101
gpu_clk off
tpu_clk off
------ Triggered Level (/vendor/bin/sh -c echo "Source\t\tLevel"; for f in `ls /sys/devices/virtual/pmic/mitigation/triggered_lvl/*` ; do lvl=`cat $f`; a=${f/\/sys\/devices\/virtual\/pmic\/mitigation\/triggered_lvl\//}; echo "${a/_lvl/} \t$lvl" ; done) ------
Source Level
ocp_cpu1 7000mA
ocp_cpu2 12000mA
ocp_gpu 12000mA
ocp_tpu 10500mA
smpl 2900mV
soft_ocp_cpu1 7000mA
soft_ocp_cpu2 12000mA
soft_ocp_gpu 12000mA
soft_ocp_tpu 10500mA
Change-Id: Ibe303ad69ffb29f3c3bbd79d557d04138cd09bd7
2021-05-20 02:07:55 +00:00
iayara
53aff191d2
Transition to using libedgetpu_util.so instead of libedgetpu_darwinn2.so.
...
bug: b/182303547
Change-Id: Ia84e63fdfdeac5094752dfe9de84b75bd56aa131
2021-05-20 00:10:01 +00:00