Commit graph

11223 commits

Author SHA1 Message Date
Adam Shih
df06cd7760 remove obsolete entries and put crucial domains to permissive
Bug: 171942789
Bug: 178979986
Bug: 179310854
Bug: 178980065
Bug: 179198085
Bug: 178980032
Test: boot to home under enforcing mode
Change-Id: Ic925dbbb74ca2ba38b22c982761c1e214886bfa1
2021-03-09 13:46:42 +08:00
Charlie Chen
4cb9150dc0 Merge changes I8de6132f,I2bc6057d into sc-dev am: e265637395
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/13775695

MUST ONLY BE SUBMITTED BY AUTOMERGER

Change-Id: Iabd11156d2fcf57c745c90353baf089417ed3984
2021-03-09 05:11:25 +00:00
Charlie Chen
e265637395 Merge changes I8de6132f,I2bc6057d into sc-dev
* changes:
  Remove dma_buf_heap tracking_denials
  Add missing permission to dmabuf_video_system_heap
2021-03-09 04:58:08 +00:00
TreeHugger Robot
5ce78ab9bf Merge "update error on ROM 7193586" into sc-dev am: ce148d20c6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/13775691

MUST ONLY BE SUBMITTED BY AUTOMERGER

Change-Id: I8be41bf126ea037a133810f05364050efa6f37f0
2021-03-09 04:48:12 +00:00
TreeHugger Robot
2d74d55108 Merge "powerstats: Add NFC, PCIE, WIFI stats" into sc-dev am: fed4fa3022
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101/+/13808282

MUST ONLY BE SUBMITTED BY AUTOMERGER

Change-Id: Id693937432530c7cfc5704f57088893414931883
2021-03-09 04:48:05 +00:00
TreeHugger Robot
ce148d20c6 Merge "update error on ROM 7193586" into sc-dev 2021-03-09 04:05:05 +00:00
TreeHugger Robot
fed4fa3022 Merge "powerstats: Add NFC, PCIE, WIFI stats" into sc-dev 2021-03-09 04:01:56 +00:00
Charlie Chen
019eec3f64 Remove dma_buf_heap tracking_denials
Bug: 182086551
Bug: 182086552
Bug: 182086686
Bug: 182086482
Bug: 182086481
Bug: 182086550
Test: atest VtsHalMediaC2V1_0TargetVideoDecTest
Change-Id: I8de6132fb41b0418f67baac4971ee03031ec3e32
2021-03-09 02:42:56 +00:00
TreeHugger Robot
a60b76aae2 Merge "sepolicy: add sensor related rules for AIDL APIs" into sc-dev am: 9c51e64c6e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/13805046

MUST ONLY BE SUBMITTED BY AUTOMERGER

Change-Id: Ic7ec7dc37858c5f79918208873bad661a6e60bda
2021-03-09 02:37:08 +00:00
TreeHugger Robot
d3cc8eaebf Merge "bootctrl: run clang-format" into sc-dev am: 9175b81a90
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101/+/13809674

MUST ONLY BE SUBMITTED BY AUTOMERGER

Change-Id: Ife96c205697f9070de3728afe2a2c22a642e03c4
2021-03-09 02:37:01 +00:00
Taehwan Kim
7d77820127 Add missing permission to dmabuf_video_system_heap
Bug: 153786620
Bug: 182086551
Bug: 182086552
Bug: 182086686
Bug: 182086482
Bug: 182086481
Bug: 182086550
Test: atest VtsHalMediaC2V1_0TargetVideoDecTest
Signed-off-by: Taehwan Kim <t_h.kim@samsung.com>
Change-Id: I2bc6057d16bbcc32ef8891f89c0440618d174982
2021-03-09 02:19:06 +00:00
TreeHugger Robot
9c51e64c6e Merge "sepolicy: add sensor related rules for AIDL APIs" into sc-dev 2021-03-09 02:03:39 +00:00
TreeHugger Robot
9175b81a90 Merge "bootctrl: run clang-format" into sc-dev 2021-03-09 01:54:41 +00:00
Adam Shih
47abac4459 update error on ROM 7193586
Bug: 182218891
Bug: 182219008
Test: pts-tradefed run pts -m PtsSELinuxTest
Change-Id: Id3d823c2ec41f9b777ccb666338a195bbd3047b6
2021-03-09 09:53:59 +08:00
Benjamin Schwartz
194edaf7db powerstats: Add NFC, PCIE, WIFI stats
Bug: 179277258
Test: adb shell dumpsys android.hardware.power.stats.IPowerStats/default
Change-Id: I64d84f82eafe34c12caeaa73f24ed79a60db3604
2021-03-09 01:40:43 +00:00
TreeHugger Robot
b33e0adb8b Merge "Fix selinux error for vendor_telephony_app" into sc-dev am: 9185f0aafd
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/13805051

MUST ONLY BE SUBMITTED BY AUTOMERGER

Change-Id: If06a9bc3c1794342f7c67eac5630cf930a761d4e
2021-03-09 01:38:24 +00:00
Benjamin Schwartz
aede81aeab Merge "Revert^2 "powerstats: Add PixelStateResidencyDataProvider"" into sc-dev am: 627a8136fc
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101/+/13809831

MUST ONLY BE SUBMITTED BY AUTOMERGER

Change-Id: I7f689ab95e54c564f8f182622d47588ca4335788
2021-03-09 01:38:08 +00:00
TreeHugger Robot
82903ddc8b Merge "trusty_apploader: Fix avc errors" into sc-dev am: c5c7a85a0d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/13805060

MUST ONLY BE SUBMITTED BY AUTOMERGER

Change-Id: Ia054941d8d4a804355e0b7a2f5008392b14528b9
2021-03-09 01:37:50 +00:00
Benjamin Schwartz
4ec52045e5 Merge "Revert "powerstats: Add PixelStateResidencyDataProvider"" into sc-dev am: 3cde50fe34
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101/+/13809353

MUST ONLY BE SUBMITTED BY AUTOMERGER

Change-Id: I3ba36a58015755a2e0648530bebd651f36e3ac0c
2021-03-09 01:37:22 +00:00
Benjamin Schwartz
627a8136fc Merge "Revert^2 "powerstats: Add PixelStateResidencyDataProvider"" into sc-dev 2021-03-09 01:31:11 +00:00
Benjamin Schwartz
5b34563d88 Revert^2 "powerstats: Add PixelStateResidencyDataProvider"
05a79631f7

Change-Id: If088251400b80a8f47b09d6f2806a3f386ea3161
2021-03-09 01:24:49 +00:00
TreeHugger Robot
9185f0aafd Merge "Fix selinux error for vendor_telephony_app" into sc-dev 2021-03-09 01:01:45 +00:00
Benjamin Schwartz
3cde50fe34 Merge "Revert "powerstats: Add PixelStateResidencyDataProvider"" into sc-dev 2021-03-09 00:58:56 +00:00
TreeHugger Robot
c5c7a85a0d Merge "trusty_apploader: Fix avc errors" into sc-dev 2021-03-09 00:55:06 +00:00
Benjamin Schwartz
05a79631f7 Revert "powerstats: Add PixelStateResidencyDataProvider"
Revert "powerstats: Create vendor state residency provider"

Revert submission 13807923-pixel provider

Reason for revert: caused build breakage

Reverted Changes:
I6b0c1d350:bthal/1.1: Use PixelStateResidencyProvider
Ia028e589b:powerstats: Create vendor state residency provider...
Id99e6d2a9:powerstats: Add PixelStateResidencyDataProvider

Change-Id: Ib1b18b5984af6b665c4ad0c9e9217a314a64e6ed
2021-03-09 00:54:23 +00:00
TreeHugger Robot
2bcc37f5cc Merge "powerstats: Add PixelStateResidencyDataProvider" into sc-dev am: 26856c61a8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101/+/13807923

MUST ONLY BE SUBMITTED BY AUTOMERGER

Change-Id: I22cfbb3c5bb87bc77619a8196ac810d9b0d7aaa4
2021-03-09 00:38:10 +00:00
TreeHugger Robot
26856c61a8 Merge "powerstats: Add PixelStateResidencyDataProvider" into sc-dev 2021-03-09 00:18:42 +00:00
Yu-Chi Cheng
d18a92b0ef Allowed the EdgeTPU service to access Package Manager binder service.
EdgeTPU service will connect to the Package Manager service
to verify applicatoin signatures.
This change added the corresponding SELinux rules to allow such
connection.

Bug: 181821398
Test: Verified using Google Camera App on local device.
Change-Id: Ia32b3de102c162e28710e0aa917831e8de784183
2021-03-08 16:02:14 -08:00
Fernando Lugo
2b75765719 bootctrl: run clang-format
Bug: 156694052
Signed-off-by: Fernando Lugo <flugo@google.com>
Change-Id: I003fb99e96bcee2d745365992b3c8d4a3816f818
2021-03-08 15:36:55 -08:00
Eric Biggers
fe9ab8c5a4 Merge changes Ia94682ee,I4da3ce85 into sc-dev am: fa50bf6c7c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101/+/13807420

MUST ONLY BE SUBMITTED BY AUTOMERGER

Change-Id: Id81d5936a8272cd1c8ff9f0d5cebfa8dbc4a4271
2021-03-08 21:58:08 +00:00
Petri Gynther
e0852fb739 gs101: build vendor_ramdisk.img am: 3c5da8c48b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101/+/13807513

MUST ONLY BE SUBMITTED BY AUTOMERGER

Change-Id: Iff808da075e4e7b212c17aa0167838c57f2a1fa1
2021-03-08 21:54:19 +00:00
Eric Biggers
c27e9e5ff9 gs101: use wrapped keys for storage encryption
Make better use of the new hardware by using wrapped keys via the KDN
(Key Distribution Network), rather than standard keys.  Wrapped keys are
slightly better protected against being compromised.

When this change is submitted, a factory reset will be required.

Bug: 149360056
Test: Booted Android and verified via the kernel log and
      'dmctl table userdata' that both FBE and metadata encryption are
      using wrapped keys.  Also ran vts_kernel_encryption_test.
      Also storage-qa and reboot stress testing (b/178650615).
Change-Id: Iab6f4199306de02b5846062e7499783b7aedf901
2021-03-08 21:23:20 +00:00
Eric Biggers
fa50bf6c7c Merge changes Ia94682ee,I4da3ce85 into sc-dev
* changes:
  gs101: remove unused fstabs for eMMC storage
  gs101: remove unneeded crypto properties
2021-03-08 21:22:50 +00:00
Benjamin Schwartz
9c9f563bd6 powerstats: Add PixelStateResidencyDataProvider
This data provider will be used to produce state residency data from
other native services that have registered callbacks.

Bug: 179277258
Test: adb shell dumpsys android.hardware.power.stats.IPowerStats/default
Test: killed power.stats and bluetooth services and verified that
providers are re-registered.

Change-Id: Id99e6d2a9300f7c7483e3fb7a6a9604a46fbbc6f
2021-03-08 11:54:56 -08:00
Petri Gynther
3c5da8c48b gs101: build vendor_ramdisk.img
aosp/1619809 has landed, so let's start building:
out/target/product/<name>/vendor_ramdisk.img

We can then easily grab ramdisk.img + vendor_ramdisk.img
from any go/ab build to our kernel dev environment.

Bug: 170687803
Change-Id: I1469fd9e545353029ceea6251dad631eab2ae1d9
2021-03-08 10:57:28 -08:00
Eric Biggers
93b740b0b0 gs101: remove unused fstabs for eMMC storage
These devices will only use UFS, so remove the emmc and sdboot fstab
files which are unused and outdated.

Bug: 181883233
Change-Id: Ia94682eecca4d792c2a50d2336cd6a542ed282db
2021-03-08 10:17:55 -08:00
Eric Biggers
3014832d9a gs101: remove unneeded crypto properties
It is unnessary to set ro.crypto.dm_default_key.options_format.version=2
or ro.crypto.volume.filenames_mode=aes-256-cts on devices with
PRODUCT_SHIPPING_API_LEVEL >= 30, since in that case these settings are
already the default.

Bug: 181883233
Change-Id: I4da3ce857a45c479e5efcee481f74031093234d8
2021-03-08 10:17:55 -08:00
Beverly
de4b2af870 Move udfps-specific config to device config.xml
Test: manual
Bug: 176550666
Change-Id: Ibaab1a4328e3559b0d0b4d7afd043a5668746ae9
2021-03-08 09:31:33 -05:00
Alessio Balsini
eb39490266 gs101: Use FUSE passthrough by default
Enable the persist.sys.fuse.passthrough.enable flag for the P21 device
configuration to enable the FUSE passthrough feature.
This feature has been enabled on Cuttlefish, Wembley and Redbull devices for
months and no issues have been detected yet.

Bug: 168023149
Test: 'adb shell getprop | grep persist.sys.fuse.passthrough.enable',
    ScopedStorageTest
Signed-off-by: Alessio Balsini <balsini@google.com>
Change-Id: I3f39b02af436f7e508bb70efc702565a667a051c
2021-03-08 12:05:36 +00:00
Isaac Chiou
73ce34397a Wifi: Add sepolicy files for wifi_ext service
This commit adds the sepolicy related files for wifi_ext service.

Bug: 171944352
Bug: 177966433
Bug: 177673356
Test: Manual
Change-Id: I1613e396fd4c904ed563dfd533fb4b8f807f9657
2021-03-08 19:36:29 +08:00
Ocean Chen
91262dd631 pixelstats: add ufs host reset count
Add path for new atom, UFS_RESET_COUNT

bug: 176740886
Change-Id: Icae0b5b104674be078854193048c3fc49f7bf527
2021-03-08 17:49:36 +08:00
joeshih
21f5312309 [P21]Phase in FactoryOta
- Phase in FactoryOta to P21

Bug: 182117971
Test: Forrest build
Change-Id: Ibd33c0c1295c420add15c708b43db2913fc55f36
2021-03-08 17:22:29 +08:00
TreeHugger Robot
a065e95101 Merge "sepolicy: add usf folder to BOARD_SEPOLICY_DIRS." into sc-dev am: cd3a13deaf
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/13805047

MUST ONLY BE SUBMITTED BY AUTOMERGER

Change-Id: I1c4d2d007c2aed0b04d33b9c6963361eda847d06
2021-03-08 09:11:36 +00:00
TreeHugger Robot
81e4375464 Merge "Allow vendor_init to set USB properties" into sc-dev am: 433719c74f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/13805049

MUST ONLY BE SUBMITTED BY AUTOMERGER

Change-Id: Ib28bddd965e4644c09ece13ec1cabd338097b581
2021-03-08 09:11:29 +00:00
TreeHugger Robot
cd3a13deaf Merge "sepolicy: add usf folder to BOARD_SEPOLICY_DIRS." into sc-dev 2021-03-08 09:02:32 +00:00
matthuang
94095e1fd3 sepolicy: add sensor related rules for AIDL APIs
SELinux : avc:  denied  { find } for pid=703 uid=1000name=android.frameworks.stats.IStats/default
scontext=u:r:hal_sensors_default:s0 tcontext=u:object_r:fwk_stats_service:s0 tclass=service_manager permissive=1
android.hardwar: type=1400 audit(0.0:24): avc: denied { transfer } for scontext=u:r:hal_sensors_default:s0
tcontext=u:r:servicemanager:s0 tclass=binder permissive=1

Bug: 182086688
Test: make selinux_policy -j128 and push to device.
Test: avc denials are disappeared in boot log.
Change-Id: I13e658c1cef3bd24ae25cc1c22dd9336b4e45b0f
2021-03-08 09:00:36 +00:00
Kris Chen
5c76e0c1f3 trusty_apploader: Fix avc errors
Fix the following avc denials:
trusty_apploade: type=1400 audit(0.0:3): avc: denied { read } for name="system" dev="tmpfs" ino=713 scontext=u:r:trusty_apploader:s0 tcontext=u:object_r:dmabuf_system_heap_device:s0 tclass=chr_file permissive=1
trusty_apploade: type=1400 audit(0.0:4): avc: denied { open } for path="/dev/dma_heap/system" dev="tmpfs" ino=713 scontext=u:r:trusty_apploader:s0 tcontext=u:object_r:dmabuf_system_heap_device:s0 tclass=chr_file permissive=1
trusty_apploade: type=1400 audit(0.0:5): avc: denied { ioctl } for path="/dev/dma_heap/system" dev="tmpfs" ino=713 ioctlcmd=0x4800 scontext=u:r:trusty_apploader:s0 tcontext=u:object_r:dmabuf_system_heap_device:s0 tclass=chr_file permissive=1

Bug: 180874342
Test: Verify no avc denied when trusty app is loaded.
Change-Id: Idbd850580220a1cb85a221d769d741f63cd8751f
2021-03-08 16:42:27 +08:00
TreeHugger Robot
433719c74f Merge "Allow vendor_init to set USB properties" into sc-dev 2021-03-08 08:38:01 +00:00
davidycchen
175299a568 dumpstate: dump more touch information
Dump more touch information for P21 projects.

Bug: 174191180
Test: trigger bugreport and check dumpstate.

Signed-off-by: davidycchen <davidycchen@google.com>
Change-Id: Ibdae06b29d8781bcc7973cb8a0ecfd0078ecde96
2021-03-08 16:24:00 +08:00
SalmaxChang
e0e29b3505 cbd: Fix avc errors am: 4d87bc0f2a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/13805045

MUST ONLY BE SUBMITTED BY AUTOMERGER

Change-Id: I088a4f7fec8e864e44f8bcb2066b21d523a60cff
2021-03-08 08:04:19 +00:00