Commit graph

1807 commits

Author SHA1 Message Date
TreeHugger Robot
f63ac851dc Merge "Add CccDkTimeSyncService" into sc-dev am: 77cbbc1237 am: ce3aeb1167 am: 33e88263c9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14273480

Change-Id: I61d0f9dd1082ec24a177adef751c4bb4d93b2a31
2021-06-04 22:18:28 +00:00
TreeHugger Robot
09c1394813 Merge "Add CccDkTimeSyncService" into sc-dev am: 77cbbc1237 am: 3c2d8cd22c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14273480

Change-Id: Id392b06f621ba4fd28770afee965d53f6b46a420
2021-06-04 22:05:20 +00:00
TreeHugger Robot
33e88263c9 Merge "Add CccDkTimeSyncService" into sc-dev am: 77cbbc1237 am: ce3aeb1167
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14273480

Change-Id: Ide671423fb2e80d07ee432efaec806dedac28dae
2021-06-04 22:04:23 +00:00
TreeHugger Robot
ce3aeb1167 Merge "Add CccDkTimeSyncService" into sc-dev am: 77cbbc1237
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14273480

Change-Id: I96d9ae4694d61f85c12cc5a7703987e2126390e4
2021-06-04 21:50:06 +00:00
TreeHugger Robot
3c2d8cd22c Merge "Add CccDkTimeSyncService" into sc-dev am: 77cbbc1237
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14273480

Change-Id: I77d39d4b2d1b2bf19407e63444c0e4fb26b6742d
2021-06-04 21:45:42 +00:00
TreeHugger Robot
77cbbc1237 Merge "Add CccDkTimeSyncService" into sc-dev 2021-06-04 21:23:24 +00:00
Hui Wang
724ea61092 Remove unnecessary rules for vendor rcs app
Bug: 190194610
Test: make, manual
Change-Id: I99f624a70a36ad6cf47806faf0eed693383dac5f
2021-06-04 14:03:31 -07:00
TreeHugger Robot
cf2f1a0ef5 Merge "whitechapel: make vframe-secure a system heap" into sc-dev am: aa7a8405e2 am: c6db38ea50 am: 8399e7d79a
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14083385

Change-Id: I6062bddff1ad3ba1746e2f21ccf01d69c352a547
2021-06-04 18:58:02 +00:00
TreeHugger Robot
eb5f332d1b Merge "whitechapel: make vframe-secure a system heap" into sc-dev am: aa7a8405e2 am: dc56bccef6 am: df281bc423
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14083385

Change-Id: I09ade82addbfef8012dca086cbcd5aee7a63e3d0
2021-06-04 18:57:53 +00:00
TreeHugger Robot
8399e7d79a Merge "whitechapel: make vframe-secure a system heap" into sc-dev am: aa7a8405e2 am: c6db38ea50
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14083385

Change-Id: Ie69fe90bb28368ec21e66ab91e0f046a4360ab40
2021-06-04 18:36:10 +00:00
TreeHugger Robot
df281bc423 Merge "whitechapel: make vframe-secure a system heap" into sc-dev am: aa7a8405e2 am: dc56bccef6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14083385

Change-Id: Ife047e32c6d92289d4e783525827e3524bd6405f
2021-06-04 18:34:36 +00:00
TreeHugger Robot
dc56bccef6 Merge "whitechapel: make vframe-secure a system heap" into sc-dev am: aa7a8405e2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14083385

Change-Id: I1923a0062cb753d9a4ce53d900a83a1eed14e59b
2021-06-04 18:21:04 +00:00
TreeHugger Robot
c6db38ea50 Merge "whitechapel: make vframe-secure a system heap" into sc-dev am: aa7a8405e2
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14083385

Change-Id: I57abe05ecdb311160459a3a3c7dc1fcdf58293ef
2021-06-04 18:19:15 +00:00
TreeHugger Robot
aa7a8405e2 Merge "whitechapel: make vframe-secure a system heap" into sc-dev 2021-06-04 18:02:34 +00:00
Sean Callanan
77432c5015 whitechapel: make vframe-secure a system heap
The GPU driver uses vframe-secure for secure allocations, so the
corresponding DMA heap file should be visible to all processes so
use the dmabuf_system_secure_heap_device type instead.

In order for this type to be used, we need to ensure that the HAL
Allocator has access to it, so update hal_graphics_allocator_default.te

Finally, since there are no longer any buffer types associated with the
vframe_heap_device type, remove it.

Bug: 182090311
Test: run cts-dev -m CtsDeqpTestCases --module-arg CtsDeqpTestCases:include-filter:dEQP-VK.protected_memory.stack.stacksize_64 and ensure secure allocations succeed
Test: Play DRM-protected video in ExoPlayer and ensure videos render correctly via MFC->DPU.
Change-Id: Id341e52322a438974d4634a4274a7be2ddb4c9fe
2021-06-04 18:01:34 +00:00
TreeHugger Robot
c9a03fd6a7 Merge "storage: update sepolicy for hardwareinfoservice" into sc-dev am: 29a5be5603 am: 86bc19fafb am: 0d618d40de
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14696013

Change-Id: I3083b3d324d10d3e657667a678391bea60a5db5e
2021-06-04 11:43:26 +00:00
TreeHugger Robot
6f18a1f6f6 Merge "storage: update sepolicy for hardwareinfoservice" into sc-dev am: 29a5be5603 am: eaa781a17f am: a6c61c6f9e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14696013

Change-Id: Ib32feb435da561e3a0d56b9b0f0229b3268b4cda
2021-06-04 11:43:06 +00:00
TreeHugger Robot
0d618d40de Merge "storage: update sepolicy for hardwareinfoservice" into sc-dev am: 29a5be5603 am: 86bc19fafb
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14696013

Change-Id: I391bc888b2c6e7abbed53c55c2e67370f5e28a89
2021-06-04 11:22:22 +00:00
TreeHugger Robot
a6c61c6f9e Merge "storage: update sepolicy for hardwareinfoservice" into sc-dev am: 29a5be5603 am: eaa781a17f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14696013

Change-Id: Ia8e362c4fb790085da4cbc470b542abcf1e6b58d
2021-06-04 11:21:30 +00:00
TreeHugger Robot
eaa781a17f Merge "storage: update sepolicy for hardwareinfoservice" into sc-dev am: 29a5be5603
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14696013

Change-Id: Iefaf730047553bbeac9788869b91679fc787c78d
2021-06-04 11:04:23 +00:00
TreeHugger Robot
86bc19fafb Merge "storage: update sepolicy for hardwareinfoservice" into sc-dev am: 29a5be5603
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14696013

Change-Id: I11ed5570c71bbb4f1dd80ff0411587aceabc6dc9
2021-06-04 11:02:36 +00:00
TreeHugger Robot
29a5be5603 Merge "storage: update sepolicy for hardwareinfoservice" into sc-dev 2021-06-04 10:45:34 +00:00
TreeHugger Robot
4861ec21c7 Merge "[RCS] Add sepolicy for RCS as non-system app" into sc-dev am: be1f56dba1 am: a19e1a15e9 am: 63fceb570c
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14719163

Change-Id: Ic8afdaffaeb418cdc5e839049d5ccbd21015d23c
2021-06-04 07:29:48 +00:00
Maciej Żenczykowski
cc9338ebec allow hal_usb_impl configfs:dir { create rmdir }; am: 729e8901ab am: f0b64bb73f am: 0c2228d79e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14542109

Change-Id: I0e75ce21fad83ed1e72a4024ef0a83cf04b5dd7b
2021-06-04 07:29:35 +00:00
TreeHugger Robot
23a53b754f Merge "[RCS] Add sepolicy for RCS as non-system app" into sc-dev am: be1f56dba1 am: 54767e9f18 am: 233f69af0e
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14719163

Change-Id: Ia0d8e8a23bd1f747d091c28362b4d246b68502ff
2021-06-04 07:29:24 +00:00
Maciej Żenczykowski
30212687d3 allow hal_usb_impl configfs:dir { create rmdir }; am: 729e8901ab am: bfebab07d6 am: df4893b27d
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14542109

Change-Id: If3e2ea7c5c6e3935aeae33612619cd4167a8c14a
2021-06-04 07:29:10 +00:00
TreeHugger Robot
63fceb570c Merge "[RCS] Add sepolicy for RCS as non-system app" into sc-dev am: be1f56dba1 am: a19e1a15e9
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14719163

Change-Id: Ia4d933dee8d7dab96a0aa3679a1c09d59e344bb9
2021-06-04 07:06:20 +00:00
Maciej Żenczykowski
0c2228d79e allow hal_usb_impl configfs:dir { create rmdir }; am: 729e8901ab am: f0b64bb73f
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14542109

Change-Id: I0d5bd327f4e91a743c7d6c43dfe76c1e7e197967
2021-06-04 07:06:10 +00:00
TreeHugger Robot
233f69af0e Merge "[RCS] Add sepolicy for RCS as non-system app" into sc-dev am: be1f56dba1 am: 54767e9f18
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14719163

Change-Id: I9a63898e64a78b2dc6de8e561144d2c66507f45b
2021-06-04 06:59:50 +00:00
Maciej Żenczykowski
df4893b27d allow hal_usb_impl configfs:dir { create rmdir }; am: 729e8901ab am: bfebab07d6
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14542109

Change-Id: I1360e670af6fd7f5efa5db9118ee24cc665568a7
2021-06-04 06:59:41 +00:00
TreeHugger Robot
a19e1a15e9 Merge "[RCS] Add sepolicy for RCS as non-system app" into sc-dev am: be1f56dba1
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14719163

Change-Id: I9b46f94b8a8b12fed6f388b5591c809f18e3adb4
2021-06-04 06:44:11 +00:00
Maciej Żenczykowski
f0b64bb73f allow hal_usb_impl configfs:dir { create rmdir }; am: 729e8901ab
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14542109

Change-Id: Idd9e05143cf953dbba1c56deedd54264d8ea6ffc
2021-06-04 06:44:01 +00:00
TreeHugger Robot
54767e9f18 Merge "[RCS] Add sepolicy for RCS as non-system app" into sc-dev am: be1f56dba1
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14719163

Change-Id: Ic7ee2c3ff0a036229000191881e0255fee2f6b56
2021-06-04 06:42:19 +00:00
Maciej Żenczykowski
bfebab07d6 allow hal_usb_impl configfs:dir { create rmdir }; am: 729e8901ab
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14542109

Change-Id: I0803ce3e0ab48c7d1f258789dcb0d3b12fc4ede6
2021-06-04 06:42:09 +00:00
TreeHugger Robot
be1f56dba1 Merge "[RCS] Add sepolicy for RCS as non-system app" into sc-dev 2021-06-04 06:22:03 +00:00
Maciej Żenczykowski
729e8901ab allow hal_usb_impl configfs:dir { create rmdir };
This is needed to allow USB HAL to create multi-config gadget
(ie. rndis + ncm).

Bug: 172793258
Test: built and booted on oriole
Signed-off-by: Maciej Żenczykowski <maze@google.com>
Change-Id: Ifb98b23138122ad4e0aeea8dd9c93d7b3e16d3aa
2021-06-04 02:53:11 +00:00
jznpark
3d127f9224 [RCS] Add sepolicy for RCS as non-system app
As shannon-rcs has been changed from system app
to non-system app, sepolicy has to be updated.

Bug: 186135775
Bug: 189707387
Test: sanity test
Signed-off-by: jznpark <jzn.park@samsung.com>
Change-Id: I32cce90611c619494136a6b1d01b3fb48330d169
2021-06-03 13:30:26 -07:00
Chiawei Wang
f5ca97f1e7 Merge "pixelstats: fix permission errors" into sc-dev am: 9cfc661bee am: a1a00508b1 am: bc80f56382
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14781915

Change-Id: I98fde1cd10a64f84cc4b3e443f921a8b5cdaa85f
2021-06-03 09:56:00 +00:00
Chiawei Wang
a8d15f6691 Merge "pixelstats: fix permission errors" into sc-dev am: 9cfc661bee am: 2d240b30a8 am: ccb61d83df
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14781915

Change-Id: Icc7d240fae4677853861260e865a68f7444898d9
2021-06-03 09:55:29 +00:00
Rick Yiu
a4dbe2ef40 gs101-sepolicy: Fix avc denials for sysfs_vendor_sched
Bug: 190011861
Bug: 190011862
Bug: 190011863
Bug: 190012301
Bug: 190012320
Test: boot to home
Change-Id: Icddb42fb194547211e33cf1d871e839a954b0919
2021-06-03 17:55:17 +08:00
Chiawei Wang
bc80f56382 Merge "pixelstats: fix permission errors" into sc-dev am: 9cfc661bee am: a1a00508b1
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14781915

Change-Id: I3c76cb431b38fc09508198ba6bfc6aef43d36493
2021-06-03 09:41:59 +00:00
Chiawei Wang
ccb61d83df Merge "pixelstats: fix permission errors" into sc-dev am: 9cfc661bee am: 2d240b30a8
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14781915

Change-Id: Ie91ad4bf9eefd33df53f9f2f26aa7b95c7cf7811
2021-06-03 09:30:21 +00:00
Chiawei Wang
2d240b30a8 Merge "pixelstats: fix permission errors" into sc-dev am: 9cfc661bee
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14781915

Change-Id: I74c9d026da00446746d0e2cbd4eb3570b99e0527
2021-06-03 09:06:10 +00:00
Chiawei Wang
a1a00508b1 Merge "pixelstats: fix permission errors" into sc-dev am: 9cfc661bee
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14781915

Change-Id: I89bbeeca2f88a9a82b5d7a1a66a70d16f79627ce
2021-06-03 09:03:14 +00:00
Chiawei Wang
9cfc661bee Merge "pixelstats: fix permission errors" into sc-dev 2021-06-03 08:45:12 +00:00
Chiawei Wang
9d5830ac19 pixelstats: fix permission errors
1. sysfs_dma_heap erros are fixed by ag/13926718
2. debugfs_mgm error is fixed by ag/14683912

Bug: 188114896
Bug: 183338421
Bug: 188495492
Test: pts-tradefed run pts -m PtsSELinuxTest
      http://sponge2/6cbd0af0-5414-4f2c-aea0-99b4981360a4

Signed-off-by: Chiawei Wang <chiaweiwang@google.com>
Change-Id: Icd2fa4e7f168d15fd4cec3000bc0e7a33eab4d3e
2021-06-03 02:52:33 +00:00
Rick Yiu
13a2d518cc Merge "gs101-sepolicy: Refine policy for sysfs_vendor_sched" into sc-dev am: b530a26f1f am: 3ad28926f7 am: 85aaaab7bb
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14774943

Change-Id: I392863914a6a87bcae0bcf5b0918372ad3d0ff10
2021-06-03 02:04:21 +00:00
Rick Yiu
92f4310aef Merge "gs101-sepolicy: Refine policy for sysfs_vendor_sched" into sc-dev am: b530a26f1f am: b6b7564259 am: ca8dc8bfe3
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14774943

Change-Id: Iac5edca6ef8448f81a82ef720cf23587576abb98
2021-06-03 02:04:10 +00:00
Rick Yiu
85aaaab7bb Merge "gs101-sepolicy: Refine policy for sysfs_vendor_sched" into sc-dev am: b530a26f1f am: 3ad28926f7
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14774943

Change-Id: Ia9a01e54849d669e01f97bff67570a3fcb2ae6c6
2021-06-03 01:37:53 +00:00
Rick Yiu
ca8dc8bfe3 Merge "gs101-sepolicy: Refine policy for sysfs_vendor_sched" into sc-dev am: b530a26f1f am: b6b7564259
Original change: https://googleplex-android-review.googlesource.com/c/device/google/gs101-sepolicy/+/14774943

Change-Id: If3c7cef9f544fd8e038969952183e7f56b76a7a2
2021-06-03 01:36:08 +00:00