Commit graph

3895 commits

Author SHA1 Message Date
Jin Jeong
0b32d1dbf3 Merge "[GS101][eSIM] Add system properties rule" into udc-dev am: 6f8bcc95aa
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/23235914

Change-Id: I4980ff6a4190956f49303993c6ba2f9b9dc84be0
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-24 01:47:12 +00:00
Jin Jeong
7b5f395f55 Merge changes from topic "esim_prop" into udc-dev am: ec56e377c5
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/23163635

Change-Id: I97904db9eb8fc3179426f237dadb427dbc0963af
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-24 01:47:04 +00:00
Jin Jeong
f75a93751f Revert "Fix LPA crash due to selinux denial" am: d569008b77
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/23167566

Change-Id: I442a10bdae030a467d31d6679864b183f32484f7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-24 01:46:58 +00:00
allieliu
192b53064b vendor_init: add esim_modem_prop am: a1f81bef7a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/23203399

Change-Id: I2871410a6d287c894b7270390967f13fc3bed2fd
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-24 01:46:54 +00:00
Jin Jeong
6f8bcc95aa Merge "[GS101][eSIM] Add system properties rule" into udc-dev 2023-05-24 01:07:11 +00:00
Jin Jeong
ec56e377c5 Merge changes from topic "esim_prop" into udc-dev
* changes:
  Revert "Fix SELinux error for com.google.android.euicc"
  Revert "Fix LPA crash due to selinux denial"
2023-05-24 01:07:11 +00:00
Jinyoung Jeong
b6d74a5196 [GS101][eSIM] Add system properties rule
Bug: 279988311
Test: https://fusion2.corp.google.com/d517f34a-3242-40b1-adf6-acb6035ff2cb , b/282901698
Change-Id: I6caed744d2bba7882f80f8ace229f6c4b4133c65
2023-05-17 06:53:34 +00:00
Jin Jeong
15e1832396 Revert "Fix SELinux error for com.google.android.euicc"
Revert submission 22899490-euicc_selinux_fix

Reason for revert: b/279988311 we rename the vendor.modem property so we don't need to add the new rules

Bug: 279988311
Reverted changes: /q/submissionid:22899490-euicc_selinux_fix

Change-Id: I72da756853a540d6251e074313b1880c9c9038e8
2023-05-16 12:18:21 +00:00
Jin Jeong
d569008b77 Revert "Fix LPA crash due to selinux denial"
Revert submission 22955599-euicc_selinux_fix2

Reason for revert: b/279988311 we rename the vendor.modem property so we don't need to add the new rules

Bug: 279988311
Reverted changes: /q/submissionid:22955599-euicc_selinux_fix2

Change-Id: I6421319ba280fb11d05f2e107754449e54e5afa4
2023-05-16 01:05:47 +00:00
allieliu
a1f81bef7a vendor_init: add esim_modem_prop
Bug: 279988311

Change-Id: I5f8759baff65073b758ce335772e72a383827d05
Signed-off-by: allieliu <allieliu@google.com>
2023-05-16 00:58:49 +00:00
Wilson Sung
618b288f0e Update SELinux error am: 20364fe3b3
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/23126085

Change-Id: Ib1b334fbdee99255b30b549f59a4f269f82ea73c
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-12 03:38:34 +00:00
Wilson Sung
20364fe3b3 Update SELinux error
Test: SELinuxUncheckedDenialBootTest
Bug: 281814691
Change-Id: I2f73f5b75aec1145dee615499a7442400defbf8a
2023-05-11 06:43:02 +00:00
Jinyoung Jeong
34495b4454 Fix LPA crash due to selinux denial am: d3a0214801
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/22948153

Change-Id: I27242c2c066012da8c2bc789a6d5eb1649929290
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 14:58:09 +00:00
Jinyoung Jeong
d3a0214801 Fix LPA crash due to selinux denial
Bug: 280336861
Test: No crash found during LPA basic tests: download eSIM,
enable/disalbe eSIM.

Change-Id: I15227415993ef3975e183f500711416f8eb8e62c
2023-05-02 11:02:39 +00:00
TreeHugger Robot
bb508c8ebe Merge "[TSV2] Remove tcpdump sepolicy from gs101 and move sepolicy to gs-common" into udc-dev am: eccb905391
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/22938599

Change-Id: I007b1d16d91540b65305e8f1b4a7e0067cf7ccdf
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-05-02 06:58:27 +00:00
TreeHugger Robot
eccb905391 Merge "[TSV2] Remove tcpdump sepolicy from gs101 and move sepolicy to gs-common" into udc-dev 2023-05-02 03:16:03 +00:00
Jin Jeong
2254323f29 Merge "Fix SELinux error for com.google.android.euicc" into udc-dev am: 5b3b2c2b1c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/22878977

Change-Id: I4cab37581a5f814b44774f7c38c1837bc8a0743d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-30 03:23:21 +00:00
Jin Jeong
5b3b2c2b1c Merge "Fix SELinux error for com.google.android.euicc" into udc-dev 2023-04-30 02:51:46 +00:00
martinwu
3785b0d271 [TSV2] Remove tcpdump sepolicy from gs101 and move sepolicy to gs-common
Bug: 264490014
Test: 1. Enable tcpdump_logger always-on function
      2. Dump bugreport
      3. Pull dumpstate_board.bin and chagne it to zip
      4. Unzip dumpstate_board.zip and check if tcpdump files
         are there.
Change-Id: Iea67de1e645592c6993a3ee6f2ca8e6bf3c6c949
Merged-In: Iea67de1e645592c6993a3ee6f2ca8e6bf3c6c949
2023-04-29 13:03:01 +00:00
Jinyoung Jeong
42a0c82065 Fix SELinux error for com.google.android.euicc
bug: 279548423
Test: http://fusion2/bb76429b-7d84-4e14-b127-8458abb3e2ed
Change-Id: I00bdf71f04eec985147189eb1b474c7ff6797023
2023-04-28 13:39:35 +00:00
Bruno BELANYI
79fa2c3fc2 Merge changes from topic "hal_neuralnetworks_armnn-selinux-exceptions - udc" into udc-dev am: 88f5acac54
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/22787136

Change-Id: I6059fc44e2edc1c80d042fb9b2977db402fe310d
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-27 08:45:09 +00:00
Bruno BELANYI
9a17c5118c Remove 'hal_neuralnetworks_armnn' sysprop exceptions am: b4001ec206
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/22786209

Change-Id: I9fb8b2f12ccbabee858c83135701e6613dfb2ecd
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-27 08:45:03 +00:00
Bruno BELANYI
b88b6bfa14 Add ArmNN config sysprops SELinux rules am: a668555419
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/22786488

Change-Id: Ia903f3d695a716f04982dbeb82ffc8368b6895e0
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-27 08:44:59 +00:00
Bruno BELANYI
88f5acac54 Merge changes from topic "hal_neuralnetworks_armnn-selinux-exceptions - udc" into udc-dev
* changes:
  Remove 'hal_neuralnetworks_armnn' '/data' access exception
  Remove 'hal_neuralnetworks_armnn' sysprop exceptions
  Add ArmNN config sysprops SELinux rules
2023-04-27 08:06:48 +00:00
Martin Wu
c7ab6cef77 Revert "Remove tcpdump sepolicy from gs101 and move sepolicy to ..." am: e30ee618d6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/22891379

Change-Id: I246f3e4ae7dd20e8eb168fa05ec30d261f1f3293
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-27 07:15:46 +00:00
Martin Wu
e30ee618d6 Revert "Remove tcpdump sepolicy from gs101 and move sepolicy to ..."
Revert submission 22814097-Fix-tcpdump-sepolicy

Reason for revert: build break

Reverted changes: /q/submissionid:22814097-Fix-tcpdump-sepolicy

Change-Id: I3d47d22250b435416c4ca44ff1956569662591ee
2023-04-27 02:20:55 +00:00
martinwu
5adb10e834 Remove tcpdump sepolicy from gs101 and move sepolicy to gs-common am: 6be45972bb
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/22814097

Change-Id: I01ec7315f92de0f793eb02dd93f884bf8094ebd7
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-27 02:17:57 +00:00
martinwu
6be45972bb Remove tcpdump sepolicy from gs101 and move sepolicy to gs-common
Bug: 264490014
Test: 1. Enable tcpdump_logger always-on function
      2. Dump bugreport
      3. Pull dumpstate_board.bin and chagne it to zip
      4. Unzip dumpstate_board.zip and check if tcpdump files
         are there.
Change-Id: I3d0cb388cf9b7c96d2856f46c0440b4017477480
2023-04-27 01:38:04 +00:00
Bruno BELANYI
9702cb57f2 Remove 'hal_neuralnetworks_armnn' '/data' access exception
The mali driver has been configured not to look there anymore.

Bug: 205779871
Bug: 264489188
Test: manual - reboot device and check the absence of AVC denials
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:347dfbe925e2218189d82d37697540af25401a22)
Merged-In: Ic8bf0d51414461689ee5768821a2a1acda923c41
Change-Id: Ic8bf0d51414461689ee5768821a2a1acda923c41
2023-04-26 17:21:18 +00:00
Bruno BELANYI
b4001ec206 Remove 'hal_neuralnetworks_armnn' sysprop exceptions
Bug: 205202540
Bug: 264489188
Test: manual - reboot device and check the absence of AVC denials
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:e4254a16aa516f5960f48732b078aad4ed63df6f)
Merged-In: Ied38dc6b323911aa909f4f42b66ee404fc7062fa
Change-Id: Ied38dc6b323911aa909f4f42b66ee404fc7062fa
2023-04-26 17:20:54 +00:00
Bruno BELANYI
a668555419 Add ArmNN config sysprops SELinux rules
Bug: 205202540
Bug: 264489188
Test: manual - reboot device and check the absence of AVC denials
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:0f99f3e63450befc661d38827e9afc853ca9257a)
Merged-In: I70c89dcc4b2bbe665d69cc4be1ac2f6cf8155a10
Change-Id: I70c89dcc4b2bbe665d69cc4be1ac2f6cf8155a10
2023-04-26 08:12:54 +00:00
Joseph Jang
9a1381585b Merge "Move recovery.te to device/google/gs-common/dauntless/sepolicy" into udc-dev am: 37e90d3f3a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/22808538

Change-Id: I21399d89048707e65eb95ba5f13c84e7d9d8ede8
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-26 04:11:52 +00:00
Joseph Jang
37e90d3f3a Merge "Move recovery.te to device/google/gs-common/dauntless/sepolicy" into udc-dev 2023-04-26 03:24:40 +00:00
Joseph Jang
ac6f4e0d00 Move recovery.te to device/google/gs-common/dauntless/sepolicy
Bug: 279381809
Change-Id: If41449f97e729053caa98930cc7f2ef9fd6d844e
2023-04-24 08:09:23 +00:00
Adam Shih
978f3f8dd8 Update error on ROM 9930000 am: 843b0ad6b4
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/22802738

Change-Id: I54760d250e690390b9c0b1f8c58e63746eb661b2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-24 03:45:31 +00:00
Adam Shih
843b0ad6b4 Update error on ROM 9930000
Bug: 277989397
Bug: 277155042
Bug: 277989067
Test: scanBugreport
Change-Id: I38a3f852e2f5f0f6895db15141825909361a267d
Merged-In: I38a3f852e2f5f0f6895db15141825909361a267d
2023-04-24 09:58:14 +08:00
jimsun
66b15bfc3d rild: allow rild to ptrace am: 26e3d2abd0
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/22122889

Change-Id: I267cad762d71cdcd7e8f7038fbcf37bc0951ffe1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-20 07:01:14 +00:00
jimsun
26e3d2abd0 rild: allow rild to ptrace
06-20 18:47:41.940000  8708  8708 I auditd  : type=1400 audit(0.0:7): avc: denied { ptrace } for comm="libmemunreachab" scontext=u:r:rild:s0 tcontext=u:r:rild:s0 tclass=process permissive=0
06-20 18:47:41.940000  8708  8708 W libmemunreachab: type=1400 audit(0.0:7): avc: denied { ptrace } for scontext=u:r:rild:s0 tcontext=u:r:rild:s0 tclass=process permissive=0

Bug: 263757077
Test: manual
Change-Id: I35ad31e6cc4e2942c671e51720f28a9abce3dcca
2023-04-18 07:48:32 +00:00
Bruno BELANYI
cb752d4cf4 Merge "Use restricted vendor property for ARM runtime options" into udc-dev am: bf8675143b
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/22381263

Change-Id: I28dbee80bce314d62708983c9f848bb61a47b1f9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-17 11:29:24 +00:00
Bruno BELANYI
bf8675143b Merge "Use restricted vendor property for ARM runtime options" into udc-dev 2023-04-17 10:59:23 +00:00
Xin Li
445c9786c6 [automerger skipped] Merge TQ2A.230405.003 am: 82232b6423 am: 26cfa34cb7 -s ours am: 9505121ada -s ours am: ab4e3e986a -s ours
am skip reason: Merged-In I8c265919f7ae4b18aa304b0a584536d2a0f4b27a with SHA-1 9828cc747a is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2530520

Change-Id: I05d9347c773c51b55bbc622ac0f3f8d9652d5782
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-12 21:13:18 +00:00
Xin Li
ab4e3e986a [automerger skipped] Merge TQ2A.230405.003 am: 82232b6423 am: 26cfa34cb7 -s ours am: 9505121ada -s ours
am skip reason: Merged-In I8c265919f7ae4b18aa304b0a584536d2a0f4b27a with SHA-1 9828cc747a is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2530520

Change-Id: I07cabb680ee2172a60bdc37f9a61a2af528844d1
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-12 20:57:06 +00:00
Xin Li
9505121ada [automerger skipped] Merge TQ2A.230405.003 am: 82232b6423 am: 26cfa34cb7 -s ours
am skip reason: Merged-In I8c265919f7ae4b18aa304b0a584536d2a0f4b27a with SHA-1 9828cc747a is already in history

Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2530520

Change-Id: Ie91202c445df25847c5bcd37cf8224e7bae6536e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-12 20:22:54 +00:00
Xin Li
26cfa34cb7 Merge TQ2A.230405.003 am: 82232b6423
Original change: https://android-review.googlesource.com/c/device/google/gs101-sepolicy/+/2530520

Change-Id: I92a1d4dff4571e4aa8f11ca6f71978d549bfc812
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-12 19:00:54 +00:00
Mike McTernan
b7ac171c15 confirmationui: Allow securedpud to access the systemsuspend HAL. am: b46b936df8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/22574497

Change-Id: Ied0ab0e2298a566992de13311b3c594f918806ce
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-12 10:21:17 +00:00
Mike McTernan
b46b936df8 confirmationui: Allow securedpud to access the systemsuspend HAL.
In order to use a wakelock, securedpud needs access to binder and the
system_suspend_service HAL.

Bug: 274851247
Test: manual, trigger TUI and check for AVC denials
Change-Id: Ibd27d32e092269f91d6557ebddcd27d4ccf1355a
2023-04-11 13:04:53 +00:00
Xin Li
82232b6423 Merge TQ2A.230405.003
Bug: 271343657
Merged-In: I8c265919f7ae4b18aa304b0a584536d2a0f4b27a
Change-Id: I61dd94e23d10e5405135626487ddadddb1f89f9f
2023-04-10 23:55:29 -07:00
Wilson Sung
1b77af6fdf Update SELinux error am: c41cb55d4f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/22530832

Change-Id: Icfd77d41de22485bb17104441431d33aaacfddef
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-10 05:24:45 +00:00
Wilson Sung
c41cb55d4f Update SELinux error
Test: scanBugreport
Bug: 277528855
Change-Id: Ia59cd4045433f2e82a602672fe533e27e87b0275
2023-04-10 11:02:52 +08:00
Adam Shih
b68badeec9 Merge "use dumpsate from gs-common" into udc-dev am: d186da49ea
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/22328249

Change-Id: Ie64d5f5b5d11b309046e0fd1ee33ee5e5fb566f9
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
2023-04-10 01:46:22 +00:00